Hi!
I am using Fortigate 5.4.4 systems, but there is a problem with the application control:
If I am running openVPN through a Fortigate, the connections are dropped from time to time, because the app changes from openVPN to Hotspot.Shield (which is blocked by a rule).
Is there any possibility to avoid this behaviour without disabling the app-ruleset?
Thank you and best wishes,
KPS
Hello KPS,
Can you get a packet capture for me? I will check it and if it's a False Positive, we will fix the signature. You can send me the file through a PM.
HoMing
Hi HoMing!
Thank you for your answer!
Can you give me a hint on how to capture these packages? The problem is, that the stream is seen ass app "OpenVPN" correctly, but after some idle-time, the classification changes from "OpenVPN" to "Hotspot.Shield". If I configure the sniffer-filter with the layer-4 filter "udp port 1194", I have tons of data on which the classification changes at some point.
Is there any possibility to capture packages and filter on "application=Hotspot.Shield"?
Thank you
Regards,
KPS
Hello KPS,
Can you send me the Application Logs and Forward Traffic Logs so I can take a look at it first? We can then decide how to filter the sniffer to catch the packets.
HoMing
I am updating the discussion here for future reference. I modified one of the Hotspot.Shield signatures to fix the false positive.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1771 | |
1116 | |
766 | |
447 | |
242 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.