Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MikeU
New Contributor

YouTube blocked as Storage.Backup/Google.Docs

We block online storage and Google Docs. Recently, about a week ago, users started complaining about problems with YouTube videos. It appears that videos, not the YouTube site, are being blocked as Storage.Backup/Google.Docs.

 

Has anyone else experienced this problem?

 

=Mike
=Mike
10 REPLIES 10
Dave_Hall
Honored Contributor

If your company allows youtube access, create an app sensor entry (set it to vendor google/Category Video/Audio) and move it up in same app sensor list, above the sensor blocking online storage and Google Docs.  Like firewall policies, app sensors are execute from top-to-bottom.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
MikeU
New Contributor

Thanks Dave.

 

We do allow YouTube. I tried adding two different sensors above any of the block sensors, without luck:

1. category=media, vendor=Google, app=YouTube, action=monitor

2. category=media, vendor=Google, subcat=audio|video, action=monitor

 

The log entry shows that the app_cat and subappcat are Storage.Backup. And, the app & subapp are Google.Docs. It's not clear to me how we can block Storage.Backup/Google.Docs using application control and still allow YouTube - which is being categorized as what we're trying to block.

 

Here's the log entry:

Message meets Alert condition

date=2014-12-31 time=13:10:32 devname= device_id= log_id=0022000003 type=traffic subtype=violation  pri=warning status=deny vd="root" src=10.0 srcname=10.0 src_port=56038 dst=173.194.7.40 dstname=173.194.7.40 dst_country="United States" src_country="Reserved" dst_port=443 service=HTTPS proto=6 app_type=N/A duration=44 rule=5 policyid=5 identidx=0 sent=623 rcvd=4592 shaper_drop_sent=0 shaper_drop_rcvd=0 perip_drop=0 shaper_sent_name="N/A" shaper_rcvd_name="N/A" perip_name="7500Kb" vpn="N/A" vpn_type=UNKNOWN(65535) vpn_tunnel="N/A" src_int="switch" dst_int="wan1" SN=330925898 app="Google.Docs" app_cat="Storage.Backup" user="N/A" group="N/A" msg="N/A" carrier_ep="N/A" profilegroup="N/A" subapp="Google.Docs" subappcat="Storage.Backup"

 

 

=Mike
=Mike
Steven_Lengua
New Contributor

Having the same issue here. Currently troubleshooting. Looks like something changed in the Fortiguard Web filtering. Let me know what you come up with and I'll share as well.

CAlengua

CAlengua
Dave_Hall

Just speculating -- it may be possible that Google may be re-organizing their IP block ranges and/or moving youtube media to the Google's storage backup, or something along those lines.

 

 

 

 

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
MikeU
New Contributor

Thanks Steve.

 

I have a support ticket open with Fortinet & will share if/when anything useful is learned.

=Mike
=Mike
Steven_Lengua
New Contributor

On hold with support now. We'll see if I can beat you to the punch. You can allow videos by Allowing the File Sharing and Storage category in your Web Filter. Of course that could cause all sorts of other issues. Ahhhh good riddance 2014!

CAlengua

CAlengua
Steven_Lengua
New Contributor

It does seem that Google updated or changed something to the detriment of others. As a workaround we allowed Google Docs in our Application Control list and then blocked Google Docs (docs.google.com) in the Web Filter. Works so far. 

 

Let me know what support comes up with for you.

CAlengua

CAlengua
MikeU
New Contributor

Still working with Support.

 

I see that the definition of the Google.Docs app was updated on 12/21. It's probably a good bet that this update is what led to YouTube videos being caught as this app.

 

http://www.fortiguard.com...applications/#id=31077

=Mike
=Mike
Dave_Hall
Honored Contributor

MikeU wrote:

I see that the definition of the Google.Docs app was updated on 12/21. It's probably a good bet that this update is what led to YouTube videos being caught as this app.

 

http://www.fortiguard.com...applications/#id=31077

With so many of Google's services (gmail, apps, storage, youtube) sharing the near/same address space, I can see why certain web filtering/app control can sometimes fail (especially with SSL only inspection and Google using the same wildcard security certificate for everything).

 

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Labels
Top Kudoed Authors