Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
HS08
Contributor

Whitelist Application Control

Hello,

 

Our user need access to 3rd party application via VPN, they use Sophos VPN for VPN client.

This traffic is blocked by fortinet because of the application control, then i make 'application and filter overrides' for OpenVPN and the user is able to connect to the VPN now.

With this condition the user can access to any OpenVPN address. Now can we restrict to only allowing use OpenVPN if the destination set to 'vpn.mycomain.com' and block the rest?

 

f2.pngf1.png

 

 

3 REPLIES 3
hulonjo1
New Contributor

Maybe wdac/app control for business is a step to far? I know that msft doesn't recommend using applocker... as no one investments will be made to improve applocker... but if you want to deploy a basic app control policy, you can take a look at my older blog about applocker

omegle xender
amuda
Staff
Staff

Hi @HS08 

 

You may set the destination in the firewall policy with this App Control profile enabled to 'vpn.mycomain.com'.

Amerul
APAC TAC
NoraSandoval
New Contributor

Thank you for being so helpful.

Spoiler
To restrict OpenVPN access to vpn.mydomain.com, create an address object for the domain in Fortinet's firewall settings. Modify your application control profile to allow OpenVPN traffic. Then, create a firewall policy permitting OpenVPN connections only to the specified domain, followed by a deny policy for all other OpenVPN traffic. Test to ensure proper functionality. I was drowning in assignments last semester and desperately needed help with a complex paper. That’s when I found essayroo.org They made everything so easy! The writer took the time to understand my instructions, and the final essay was exactly what I needed. It was well-written and delivered right on time. I’m really happy with the service and will continue to use them in the future.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors