I am looking for advice on how to deal with Adobe Creative Cloud.
Fortinet provided information (Internet Services, etc.) unfortunately seem not complete.
I need to close down all unnecessary traffic from inside to the internet.
One of the policies should deal with Adobe Creative Cloud, but I can't make it work reliably.
I tried a combination of Adobe Internet Services and Security Profiles:
Interestingly, those blocked connections were labeled as Adobe...
Examples are
13.224.92.48 (static.adobelogin.com) -> Amazon-AWS (but not any Adobe Internet Service...)
2.21.22.155 (helpx.adobe.com) -> Akamai-CDN (but not any Adobe...)
40.126.31.136 (www.tm.a.prd.aadg.akadns.net) -> Suspect Adobe usage, but I'm not sure
162.247.242.19 (bam.nr-data.net) -> New Relic (but not any Adobe...)
there are more..
For some of those I checked Adobe Acrobat DC with procmon looking at the IP connections opened directly on one of the PC's. Obviously I cannot directly link back to the above FQDN's as I only see PTR records in procmon.
Fact is that I, despite using the Fortinet provided Internet Services and the Application Profile, I can't make Adobe Cloud working correctly. But I do not want to keep everything open.
So, what might be your advise on how I can approach this?
Thanks
Dan
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Dan,
The most important two features implied are 'detection' and 'blocking', and we need to find out where it fails.
To correctly detect the HTTPS traffic, you need proxy-mode policy, Application control profile, "deep-inspection" SSL-SSH profile, and possibly Webfilter profile as well.
In some of your tests it seems that you managed to get the detection working, but blocking is effective on other profiles - need to see what security feature is blocking these sites (in logs). Some of the domains may not be allowed by allowing only Adobe (AWS/Akamai..) - these may be used by other sites as well, therefore may fall in the blocking category for those.
This being said, a better approach is to block unwanted specific elements/domains/categories rather than allow only specific domains.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1661 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.