Ihave one rule allow with all des and all service, filter with application control and web filter. Application control allow viber and web filter only allow some website. When use this rule, user only chat viber and can't send image to other user. Please help me to fix this error.
Well, I had the same problem too. But, you can solve it by adding SSL from Network.Services Category in Application Override, then allow it. The drawback is it when you allow it, VPNs will be able to use and bypass the restrictions. Hope, it's helpful.
Most application control profiles will require SSL Deep Inspection to work properly. You can see for the details of Viber it uses some unencrypted protocols (HTTP) and some encrypted (SSL). Without SSL Deep Inspection, Application Control will only see the unencrypted protocols for Viber and everything else will just be seen as "SSL". This is why the other user made it work by setting application override for SSL. This is not what you want to do tho as it will introduce other issues becuase a lot of things use SSL.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
You may not have to do anything that drastic. Try deleting the viber app, then restart your phone before adding it back. Just a normal restart or a forced restart (neither will result in any data loss)
I tried to apply some web and application policy to block peer to peers anonimyzers and social networking however it blocks users to send image on viber. I already allowed viber on the application rule. Only image is blocked. Which tule is blocking it?
Hi Ihenock
What is the status if you create a clone rule of same rule( above to this existing rule) and select any one device IP and remove the web filter? Is it working fine for that device IP which is part of clone rule?
OR
Create a similar kind of rule on top for any one device IP and apply only App filter and confirm the status. If it is working fine then apply the "Allow All" web filter and confirm the status.
If the above works then remove Web filter "Allow All" and apply the web policy on this test rule which you have applied on original rule:This will give you hint where content getting blocked. If applying the same web filter on that rule creating a problem then any category inside the Web filter matching any URL and blocking the traffic due to block action set for that category inside the policy.
3a8082e126