Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
12312321331ewfaeffds
New Contributor

Linkedin blocked by IPS

Hello,
My linkedin today was blocking by Intrusion Prevention security profile.

But we know that linkedin is a safe website.

How we can bypass or fix it to not block linkedin?

Thanks guys, there is below the message.

Attack Name WebRTC.Local.IP.Addresses.Disclosure
Attack ID 40.038
Reference https://fortiguard.fortinet.com/encyclopedia/ips/40038
Incident Serial 824.415.275
Direction incoming
Severity
Low
Message web_app3: WebRTC.Local.IP.Addresses.Disclosure

2 REPLIES 2
Atul_S
Staff & Editor
Staff & Editor

Hi There,

 

If it's a one off situation, you may avoid this since even if we try to find a reason for this issue, we could not do so since the issue is not occurring anymore.

 

However, if the issue reoccurs while using Chrome or Firefox, pls try to use the Edge browser at the same time for the same website and see if you notice any behavior change.

 

Thanks,

Atul Srivastava
Durga_Ashwath

Hi,
To bypass or fix the issue of LinkedIn being blocked by the Intrusion Prevention Security Profile, follow these steps:

1.Check the IPS signature details for `webrtc.local.ip.addresses.disclosure` (Attack ID 40.038) on the FortiGuard Encyclopedia to understand its purpose and impact.

2. Modify the IPS Profile:
- Go to the FortiGate GUI.
- Navigate to `Security Profiles` > `Intrusion Prevention`.
- Edit the IPS profile that is currently applied to your traffic.

3. Within the IPS profile, locate the signature `webrtc.local.ip.addresses.disclosure`.
- Create an exception for this specific signature to prevent it from blocking LinkedIn traffic.

4.After making changes, test the configuration to ensure LinkedIn is accessible and that the exception is working as intended.

5.Continuously monitor the traffic logs to ensure no other legitimate traffic is being blocked.
- Adjust the IPS profile settings as necessary to maintain security without impacting legitimate access.

Please do follow the below article:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-block-LinkedIn-Jobs/ta-p/271596

https://forum.fortinet.com/tm.aspx?m=151871
Quarantine list is maintained by kernel and is more efficient in cpu usage in terms of blocking quarantined client connections.

Thank you.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors