Fortigate: Tutorial uso de Application Control

 

Application Control is a next generation feature from Fortigate that allows you identify, monitor and manipulate Layer 7 (Application) traffic very easily in the Firewalls (F.e. traffic like Facebook, Salesforces, Office 365, etc).

This feature works in conjuction with Fortianalyzer which can provide Network monitors and graphs showing Bandwidth utilitzation, number of sessions, and


Application Control configuration in the Fortigate firewall

Go to Application Control under Security Profiles

 

Create a new Application Sensor

1.JPG

Note the different Application categories that are displayed under the Sensor. Inside each category we will find many different known applications such as:

- Collaboration (Microsoft Teams, Skype for Business, Cisco Jabber...)

- SocialMedia (Facebook, Instagram, Twitter...)

- CloudIT (AWS, Azure, etc)

2.jpg

As mentioned above, we can manipulate the Application traffic using any of the following the following actions:

- Monitor -> This action allows the targeted traffic to continue on through the FortiGate.

- Allow -> This action allows the targeted traffic to continue on through the FortiGate unit but logs the traffic for analysis.

- Block ->This action prevents all traffic from reaching the application and logs all occurrences.

- Quarantine -> This action allows you to quarantine or block access to an application for a specified duration that can be entered in days, hours, and minutes. The default is 5 minutes.

3.JPG

We can also apply features/actions on specific applications under Aplications Overrides (f.e.: If we want to add a Traffic Shaper policy just for Skype for Busines traffic only).

Alternatively, if we want to filter any specific Application traffic it needs to be defined under Filter Overrides.

Very Important to Allow QUIC as it's a protocol used in Google Chrome browser!

4.JPG

Once the Sensor is created, we just simply need to apply it on a Firewall Policy like for example a Policy that permits access to the INTERNET. And we are done !

5.JPG

On FortiAnalyzer under SOC > Fortiview > Applications & Websites we will be able to see Application monitoring based on the Sensor and the FW Policy we created

Comentarios

Entradas populares de este blog

EVE-NG: Instalación de EVE-NG

Fortigate: Capturar paquetes (Packet capture/sniffer)

Cisco ISE | Certificados SSL públicos para Guest Portal