Application Control
Configuring an application control list
FortiGate Version 4.0 Administration Guide
01-400-89802-20090424
525
•
Figure 346: The create a new application control list dialog window
Configuring an application control list
To configure an application control list, go to
UTM > Application Control > Control List
and
select the
Edit
icon of the list you want to configure.
The FortiGate unit examines network traffic for the application entries in the listed order,
one at a time, from top to bottom. Whenever a match is detected, the action specified in
the matching rule is applied to the traffic and further checks for application entry matches
are stopped. Because of this, you can use both actions to create a complex rule with fewer
entries.
For example, if your organization has standardized on AIM for instant messaging, you can
allow AIM and block all other IM clients with just two entries. First, create an entry in which
AIM is the specified application. Set the action to
Pass
. Then create an entry in which the
Category
is
im
, the
Application
is
all
, and the action is
Block
. Since the entries are
checked from top to bottom, AIM traffic will trigger the first rule, and be passed. All other
detected IM traffic will trigger the second rule, and the FortiGate unit will block it.
Figure 347: Editing an application control list
Name
Enter the name of the application control list.
Comments
Optionally, enter a comment or description.
Name
The name of the application control list.
Comments
Enter or edit a comment about the list. The comment is optional.
Other Applications
Other applications are those the FortiGate unit does not recognize, or
applications that are recognized but not configured in the application
control list. You can select whether to block or allow other application
traffic, and also whether to log it.
Action
Select the action the FortiGate unit takes with other application traffic.
Log
Select whether the FortiGate unit will log other application traffic.
Create New
Select to create a new application entry.
Summary of Contents for Gate 60D
Page 705: ...www fortinet com...
Page 706: ...www fortinet com...