Webfilter with SSL Inspection blocking Audio and Video in Google Hangouts
We're using a 600D, version 5.4.1 and we have a new network segment we are moving some users to. This network is somewhat restricted on content so we enabled the webfilter and are blocking a good bit of stuff. We turned on the SSL inspection with the "Certificate Inspection" profile which is supposed to be a nice light touch and not get in the way with certificate warnings. The main issues is our users communicate with Google Hangouts and make audio/video calls with it frequently. The text side of hangouts is working fine however when making calls, the call will connect but never pass audio/video through. I thought there might be a web filter category blocking that aspect so I stated unblocking items. I got very drastic and ended up unblocking EVERYTHING, but the audio/video never goes through until we turn off SSL certificate inspection. With certificate inspection turned off audio/video is working again. We're now back to the original setting with the category filters on but the ssl inspection off. This is not ideal because most user are smart enough to know to use https when they get blocked.
Ok, so this may in fact not be a webfilter question. So currently that network is only allowed to connect out on http, https, and ping. What service should be added to allow the Hangouts audio/video communication? I looked up STUN but it was not listed in the services and I have not found much info online about how to go about unblocking it. Is there another service such as SIP that should be allowed?
From what I know, Hangout will firstly try to use the UDP port ranges, fallback to the TCP onces and as a last resort use http and https. Using UDP ensures the less latency on video and audio calls so you should open those at least.
Also I know that Hangout has issues with explicit proxies, this might explain why it doesn't work when you enable SSL Certificate inspection as your firewall might be in "proxy mode".
So I would try this setup:
Keep the SSL certificate inspection & the web filtering;
Open at least the UDP ranges;
In this case, Hangout won't default to the http or https protocols to communicate and will use the fastest way which is through the UDP protocol.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.