Application Control
What is application control?
FortiGate Version 4.0 Administration Guide
01-400-89802-20090424
523
•
Application Control
This section describes how to configure the application control options associated with
firewall protection profiles.
If you enable virtual domains (VDOMs) on the FortiGate unit, the application control
configuration of each VDOM is entirely separate. For example, application lists created in
one VDOM will not be visible in other VDOMs. For details, see
This section describes:
•
•
FortiGuard application control database
•
Viewing the application control lists
•
Creating a new application control list
•
Configuring an application control list
•
Adding or configuring an application control list entry
•
Application control statistics
What is application control?
Using the application control UTM feature your FortiGate unit can detect and take action
against network traffic depending on the application generating the traffic. Based on
FortiGate Intrusion Protection protocol decoders, application control is a more user-
friendly and powerful way to use Intrusion Protection features to log and manage the
behavior of application traffic passing through the FortiGate unit. Application control uses
IPS protocol decoders that can analyze network traffic to detect application traffic even if
the traffic uses non-standard ports or protocols.
The FortiGate unit can recognize the network traffic generated by a large number of
applications. You can create application control lists that specify the action to take with the
traffic of the applications you need to manage and the network on which they are active.
Add application control lists to protection profiles applied to the network traffic you need to
monitor.
FortiGuard application control database
Fortinet is constantly increasing the list of applications that application control can detect
by adding applications to the
FortiGuard Application Control Database
. Because intrusion
protection protocol decoders are used for application control, the application control
database is part of the
FortiGuard Intrusion Protection System Database
and both of
these databases have the same version number.
To view the version of the application control database installed on your FortiGate unit, go
to the
License Information
dashboard widget and find IPS Definitions version.
To see the complete list of applications supported by FortiGuard Application Control go to
the
FortiGuard Application Control List
. This web page lists all of the supported
applications. You can select any application name to see details about the application.
Summary of Contents for Gate 60D
Page 705: ...www fortinet com...
Page 706: ...www fortinet com...