We have security policies in place to block social media applications. However, in the past few days, these applications have been accessible without any restrictions. Upon investigation, we found that traffic over SSL and QUIC is being allowed for these sites. Please assist us in fully blocking access.
Model : FortiGate 60F
Firmware : v7.2.10 build1706 (Mature)
Application Control Policy :
Web URL Filter Policy :
Log in which we can see that the websites are getting allowed :
I think QUIC is a curse and should always be denied.
Try deny it and see if it helps.
Hi AEK,
Thanks for the reply, can you help me out with the steps to deny QUIC protocol and is there any chance that it might impact port 80 and 443.
create a service with the protocol UDP and port 443 and deny it in a rule to the Internet. This new rule must be positioned above the existing rule for access to the Internet.
You can do like explained by FortiMentor, or you can also add an override to the used Application Control profile to deny the QUIC application, just like what you did for Facebook, Instagram and so
User | Count |
---|---|
2561 | |
1357 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.