Hi all, we are running Fortigate 100D here with v5.4.0,build1011 (GA).
We are running on 3 VLAN where 3 have different webfiltering & application control set up.
After the set up of the security profile. My user was complaint that they can make a call/video call via IMO instant messaging. They also unable to download/share the photo/image through wechat.
The configuration in my application control->default->Collaboration is set to allow. Video/audio is allowed, VOIP is allowed too.
I had add the application to application override and set to allow too.
But they still unable to make call and share the photo.
Can you all give me some advise please. Thank you.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
[&o] no one able to help?
Are the destination IPs always the same? Perhaps an exemption to make it work properly that is placed above this app control rule?
Mike Pruett
Hello Adrian,
I looked into the issue and the reason both applications do not work well is because some of the sessions were not identified properly. With the WeChat picture transfer, the new update modified the protocol slightly. The signature has been modified to a more generic one to cover both old cases and the latest one.
As for Imo, the signature did not cover the video calling sessions. I analyzed the protocol and added new signatures for it. They should be released in the IPS Definition scheduled for tomorrow. Sorry for the inconveniences!
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.