add_app_control_rule
Adds a rule to an application control profile on FortiGate, matching apps or categories by name or ID. Inserts at top by default; only affects policies using that profile.
Instructions
Add a rule to an app-control profile matching applications and/or categories by name (or id). Rules are checked top-down and the built-in profiles start with a catch-all pass rule, so new rules are inserted at the top by default (position=bottom to append). Only affects policies whose application_list is this profile.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| log | No | Log matches (default true) | |
| vdom | No | VDOM (default: FORTIGATE_VDOM, usually root) | |
| action | No | block, pass, monitor (default) or reset | |
| profile | Yes | Profile name, e.g. default | |
| position | No | top (default) or bottom | |
| categories | No | Category names or ids, e.g. [P2P, Proxy] | |
| applications | No | Application names or ids, e.g. [YouTube, BitTorrent] |