We want to allow MS Teams from a top Firewall Rule and to allow other applications I want to forward the request to other Firewall rules instead of denying immediately
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello!
I am not sure how you would like to achieve that in a FortiGate.
Once the policy is matched, the application control will give the verdict : either allow(monitor) or deny. There is no configurable action to pass the scanning to another policy, because this has already been matched
Actually I am facing a lot disconnection sometimes on MS Teams and now think that I should allow only Teams without applying any AV, IPS or other Security Profile on Firewall Rule for MS Teams.
In short I don't want to apply any Security Profile against only MS Teams application
Understood now. Check if this App Control profile helps as TOP policy.
You can also deny MSTeams in all previous policies, and use this as a bottom policy.
(deep inspection may be required)
I would also take a look at these three links as they mention Teams dropping calls behind a FortiGate.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Microsoft-Teams-calls-dropping/ta-p/230203
Then a general common issues link one of the other links provided, links to
You can't use app control profiles to globally restrict access to applications.
You'll probably need to use ISDB instead of app control here...
But also it might be better if you can give us more details as to what exactly you are trying to accomplish?
You can enable Internet Service in the Top Rule with all MS-TEAMS service.
ISDB is the best approach as long as this identifies correctly all MS.teams IPs.
Is this solution enough for you or do you still need help?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1705 | |
1093 | |
752 | |
446 | |
230 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.