Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
lnguyen
New Contributor

WAF known exploit signature blocking prime video on iOS

Just in case someone runs into this same issue. We ran into a problem where users were complaining prime video would not load on their apple devices. Turns out the "Known Exploit" signature is blocking the videos but not the app itself. Turning off the specific signature fixes the issue. Not sure if this is intended or a false positive.

 

 

Absolute Date/Time2021/07/14Time16:06:22Session ID334183039Virtual DomainrootAgentPrime%20Video/8.330.7424.12

 

ActionblockedPolicy ID17

 

Profile NameTest FilterEvent ID90300017DirectionrequestSeverity MessageKnown Exploits

Log ID1200030248TypeutmSub TypewafEvent Typewaf-signatureSource Interface RolelanDestination Interface Rolewan
1 REPLY 1
atakannatak
Contributor II

Hi @lnguyen ,

 

The issue you're encountering with Amazon Prime Video on iOS being blocked by the FortiWeb is likely caused by a false positive triggered by the "Known Exploit" signature. FortiWeb uses signatures to detect and block known exploits, but sometimes legitimate traffic can be mistakenly flagged as malicious. In this case, the Prime Video content request likely resembled a pattern associated with a known exploit, causing the WAF to block it, while the app itself was still functional. Disabling the specific signature resolved the issue, suggesting that the WAF's detection rule was too broad or incorrectly classified Prime Video’s traffic.

 

To address this, you can update the FortiWeb signature database to ensure it includes the latest rules that may help prevent such false positives. Additionally, customizing the WAF profile to fine-tune the blocking rules—by disabling only the problematic signature or creating a custom profile for Prime Video traffic—would allow you to prevent these disruptions without compromising security. However, it's important to continuously monitor the WAF for any new false positives or missed exploits, as turning off specific signatures could weaken the protection against actual attacks.

 

Finally, if you can share the attack log information related to the blocking, such as the signature ID or a full screenshot of the log, we can perform a more detailed analysis together to better understand the issue. If further analysis is needed, you can also report the issue to Fortinet support for additional assistance in tuning the signature to prevent similar problems in the future.

 

BR.

 

If my answer provided a solution for you, please mark the reply as solved it so that others can get it easily while searching for similar scenarios.

 

CCIE #68781

Atakan Atak
Atakan Atak
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors