4.4.3 Ensure all Application Control related traffic are logged

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Ensure no category is set to 'Allow' on FortiGate Application Control.

Rationale:

Any category that is set as 'Allow' on Application Control will not be logged. This creates visibility gap on security investigation. This includes 'Unknown Applications' category.

Impact:

Visibility gap, affects incident forensics and response.

Solution

Review Application Control Security Profiles and validate that no 'Allow' action is set on any categories.

Default Value:

'Unknown Applications category is set as 'Allow'