Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
A_Username
New Contributor

Netskope Custom Application Signature

Hi,

 

We are using Netskope and for Chromebooks it uses a Proxy, which appears to be blocked by the Proxy group, which we need to keep enabled.

 

How do we create a custom application signature for Netskope and allow it for Application, DNS & Web Filtering so it functions properly.

Blocking applications with custom signatures | FortiGate / FortiOS 7.2.9 | Fortinet Document Library

 

I was looking at above and thinking of doing an Allow, but not sure what the signature portion needs for values.

 

Has anyone does this and have instructions we can follow?

 

Thanks.

2 REPLIES 2
A_Username
New Contributor

Hi,

 

For the application signature we need to allow:
gateway-kcdsb.goskope.com tcp-443
gateway-backup-kcdsb.goskope.com tcp-443
addon-kcdsb.goskope.com tcp-443
download-kcdsb.goskope.com tcp-443
achecker-kcdsb.goskope.com tcp-443
eproxy-kcdsb.goskope.com port 8081
vpn-kcdsb.goskope.com tcp-443
sfchecker.goskope.com tcp-443

 

I'm thinking it would be something like:
F-SBID(--name "Netskope.Custom";--protocol tcp,udp; --service http,https; --dst_port 443,8081; --flow from_client; --pattern ".goscope.com"; --context host; --distance 0,context; --no_case; --pattern "/v/"; --context uri; --within 15,context; --no_case; --context uri; --distance 0; --weight 20;--app_cat <#>;)

 

Not sure if the syntax is correct and for app_cat what would I replace <#> with to have it go under Cloud.IT?

 

Thanks.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors