Just in case someone runs into this same issue. We ran into a problem where users were complaining prime video would not load on their apple devices. Turns out the "Known Exploit" signature is blocking the videos but not the app itself. Turning off the specific signature fixes the issue. Not sure if this is intended or a false positive.
Absolute Date/Time2021/07/14Time16:06:22Session ID334183039Virtual DomainrootAgentPrime%20Video/8.330.7424.12
ActionblockedPolicy ID17
Profile NameTest FilterEvent ID90300017DirectionrequestSeverity MessageKnown ExploitsLog ID1200030248TypeutmSub TypewafEvent Typewaf-signatureSource Interface RolelanDestination Interface Rolewan
Hi @lnguyen ,
The issue you're encountering with Amazon Prime Video on iOS being blocked by the FortiWeb is likely caused by a false positive triggered by the "Known Exploit" signature. FortiWeb uses signatures to detect and block known exploits, but sometimes legitimate traffic can be mistakenly flagged as malicious. In this case, the Prime Video content request likely resembled a pattern associated with a known exploit, causing the WAF to block it, while the app itself was still functional. Disabling the specific signature resolved the issue, suggesting that the WAF's detection rule was too broad or incorrectly classified Prime Video’s traffic.
To address this, you can update the FortiWeb signature database to ensure it includes the latest rules that may help prevent such false positives. Additionally, customizing the WAF profile to fine-tune the blocking rules—by disabling only the problematic signature or creating a custom profile for Prime Video traffic—would allow you to prevent these disruptions without compromising security. However, it's important to continuously monitor the WAF for any new false positives or missed exploits, as turning off specific signatures could weaken the protection against actual attacks.
Finally, if you can share the attack log information related to the blocking, such as the signature ID or a full screenshot of the log, we can perform a more detailed analysis together to better understand the issue. If further analysis is needed, you can also report the issue to Fortinet support for additional assistance in tuning the signature to prevent similar problems in the future.
BR.
If my answer provided a solution for you, please mark the reply as solved it so that others can get it easily while searching for similar scenarios.
CCIE #68781
User | Count |
---|---|
2593 | |
1381 | |
800 | |
659 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.