Skip to main content
Kevin_Noble
New Member
April 7, 2017
Question

Anybody having trouble with Data Leak errors with 5.6.0

  • April 7, 2017
  • 1 reply
  • 6912 views

We tried to run 5.6.0 on one of transparent firewalls and it ended up blocking access for some users and coming up with data leak errors even if we had no DLP enabled in the policy.  Has anybody else experienced anything like that with 5.6.0?

    1 reply

    GoDannY
    New Member
    April 24, 2017

    I have actually the same problem but running Proxy/NAT Mode with explicit proxy . Maybe it is the same actual scenario - I even have some users quarantined through DLP when they reach a certain treshold for some reason - most of them being "Blocked by Firewall-Policy" when I look into my threat dashboard, yet not nearly enough DLP events...

     

    Is it the same on your end?

     

    renedubs
    New Member
    May 8, 2017

    I have the same. The Fortigate put these hosts into quarantine. You may find them on "User Quarantine Monitor". - In My case the list entrys will expire in the past (Year 1936) !!! That looks like a bug.

     

    But the reason is not clear. I never used "quarantine IP" into the DLP policy.

    dpaech
    New Member
    May 24, 2017

    Same here. We never used the option "quarantine ip" in DLP, but have also the strange behaviour in DLP-Log in "DLP Extra" Column as it is described in this another post!