Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
waaalex
New Contributor III

Skype connection issue (skype can't connect)

Hello all,

I've got a problem with Skype connection. Sometimes it works and sometimes skype can't connect without any clue..

 

On application control, i've granted acces to Skype

 

I've set a rule that use appsensor, and open a port.

 

 

But it change nothing. sometimes i can conenct slype but sometimes no..

 

Have you got an idea?

 

Regards,

Alexandre

2 Solutions
vmartin_FTNT
Staff
Staff

Are you using full SSL inspection (the deep-inspection profile). If you are, you may need to add an exemption, to make sure Skype traffic is not being inspected.

Technical Writer, FortiOS

Let me know if there's anything you want to see added to the FortiGate Cookbook.

View solution in original post

waaalex
New Contributor III

Hello, thank you for answer but it change nothing.

It works for some users but not for some other.

In my IPv4 rule, 0 bytes are counted.

It drives me crazy ^^

 

Edit : I've disabled my rule and made change on certificate inspection for the rule HTTPS. It seems that skype pass by 443.

It works on all 4 test users.

I will test again for a week and let you know if it's ok :)

Thank you very much

View solution in original post

10 REPLIES 10
mramon79
New Contributor

Hi,

a have been testing for many weeks to try block /allow skype depends of our different user profiles and i can say Skype is such a pain in the neck.

I´m going to explain how i have configured the Fortigate to block/allow this application in 5.2.2 and 5.2.3 v, and it works ok.

You can access skype 3 ways:

1)specific application with skype user

2)specific application with hotmail  user

3)from outlook web interface

 

I use Fortigate as explicit web proxy and application control run before web filter(Fortigate documentation about traffic flow tells the opposite but this is only for fortigate in firewall mode).

 

If you want to allow it:

1) Application control, Categories P2P and Collaboration blocked and create an Application Overrides for Skype

2) In web filter Section-->Fortiguard Category "Internet Telephony" Allow and enable the following url filter:

        \.trouter\.io            Reg Expression      Enable

        .*skypeassets.com  Reg Expression    Enable

        skype.com               Simple              Enable

 

If you want to block the application only do the opposite.

 

I hope this may help you

 

Regards

 

 

Labels
Top Kudoed Authors