LAB 8 - Application Control
LAB 8 - Application Control
© FORTINET
Lab 8: Application Control
In this lab, you will configure and use the application control in policy-based mode, to apply an appropriate action
to specified application traffic. You will the view the generated logs.
Objectives
l Configure and test application control in NGFW policy-mode.
l Read and understand application control logs.
Time to Complete
Estimated: 15 minutes
Prerequisites
Before beginning this lab, you must restore a configuration file to Local-FortiGate.
In NGFW policy-based mode, application control is applied directly on a firewall policy, without the use of an
application control profile.
In this exercise, you will configure application control on a FortiGate operating in NGFW policy-based mode.
You will be configuring a new firewall policy and applying application control on the policy.
Field Value
Name Social_Media_Block
Source all
Destination all
Service ALL
Application Social.Media
Tip: From the right pane, click Category and then search for
Social.Media.
© FORTINET
Field Value
Action DENY
6. Click OK.
7. From the ID column, drag the Social_Media_Block firewall policy above the ALLOW_ALL firewall policy.
Your firewall policy order should look like this:
© FORTINET
When applying application control, you should have a policy that allows all
applications. Otherwise, you allow only specific applications and all other applications
(including web browsers) will be blocked.
Now that your configuration is complete, you will test application control by going to the application that you have
configured.
2. Try to visit websites that fall under application categories other than social media, such as http://dailymotion.com.
The pages load.
3. Return to your browser tab where you are logged in to the Local-FortiGate GUI, and click Log & Report >
Application Control.
The Application Control logs section will not display if there are no application
control logs. FortiGate will show the section after creating logs. If the Application
Control menu item does not display in the GUI, refresh your browser or log out of the
Local-FortiGate GUI and log back in.