Skip to main content
Contributor
March 7, 2005
Question

Blocked files problem

  • March 7, 2005
  • 9 replies
  • 6530 views
Hi! We have a 200 with the latest firmware. I have added *.exe (and about 40 other file types) to the list of blocked files. In Protection Profile I have a profile named " scan" in which File Block for SMTP is set. In the SMTP policy for the mail server I have set " scan" as the protection profile. You guess it: Incomming emails with .exe attachments are not blocked by the firewall. Can someone please help?!? Cheers Oliver

    9 replies

    Contributor
    March 8, 2005
    hi, see anti-virus , file block and enable in smtp *.exe that' s work fine.
    Contributor
    March 9, 2005
    yeah, If that doesn' t work. maybe your mail server is hosted outside the firewall and incomming mails come from POP3. in that case file block on pop3 too.
    Contributor
    March 9, 2005
    Thanks, but as I wrote everything is enabled. And we do have our own exchange server working with SMTP. I just rechecked it. The funny thing is, that some emails from spammers got blocked due to *.scr attachments which got quarantined. On the other hand I just sent me an file test.scr with a webmailer (web.de) and this attachment went through ... the testfile is a text document renamed with the commando shell from test.txt to test.scr. This is what I do not understand. Could it be, that HTML-Mails with attachments do not get checked? I will try to send me an test mail in text only. Oliver
    Contributor
    March 9, 2005
    Rechecked it with a webmailer sending in plain text. Either an attached .scr and a .exe went through. So why the heck are some attachments blocked and others of the same type go through. I am lost ... Oliver
    Wayne11
    Explorer
    March 11, 2005
    I have sometimes the same problem http://support.fortinet.com/forum/tm.asp?m=6655&appid=&p=&mpage=1&key=&language=&tmode=1&smode=1&s=#6655
    Contributor
    March 11, 2005
    " Glad" to hear that it is not me. I sent I bug report to Fortinet but they ignore it. Seems to me that there service from former times is gone. Nobody with a solution for this error? Best Oliver
    Contributor
    March 11, 2005
    giessler: Can you post a bit of your Anti-Virus log? I would like to see some of the entries, specifically the ones where it was blocking .scr files from some e-mail.
    Contributor
    March 12, 2005
    Sure, here we go: 5 2005-03-10 11:37:12 warning 217.87.136.18 192.168.0.1 external internal The file your_archive.pif is blocked. 6 2005-03-10 09:42:15 warning 192.168.0.11 213.191.73.2 internal external The file upd02.com is blocked. 7 2005-03-10 09:42:15 warning 192.168.0.11 213.191.73.2 internal external The file wsd01.com is blocked. 8 2005-03-10 09:29:45 warning 217.184.17.50 192.168.0.1 external internal The file readme_lippert.zip is infected with W32/Netsky.P-mm. ref http://www.fortinet.com/VirusEncyclopedia/search/encyclopediaSearch.do?method=quickSearchDirectly&virusName=W32%2FNetsky.P-mm. 9 2005-03-10 09:29:33 warning 217.184.17.50 192.168.0.1 external internal The file message.scr is blocked. 10 2005-03-10 09:29:33 warning 217.184.17.50 192.168.0.1 external internal The file is infected with W32/Netsky.P-dr. ref http://www.fortinet.com/VirusEncyclopedia/search/encyclopediaSearch.do?method=quickSearchDirectly&virusName=W32%2FNetsky.P-dr. 11 2005-03-10 09:22:47 warning 217.184.17.50 192.168.0.1 external internal The file number_phone_product.txt.exe is blocked. I just sent one of the blocked pifs as an attachment with an webmailer to my account ... it went through ... Edit: I tried to send the very file from my internal account back to the webmailer ... then it got blocked by the firewall ... Thanks for your help! Oliver
    Contributor
    March 30, 2005
    Hi, I' m new to Fortinet but have the same issue but with downloading certain files. I have .exe blocked as well, scan in the protection file, but I can still download .exe files. What' s the deal? I have the latest code build. Tony
    rschulz
    New Member
    April 4, 2005
    Although this is slightly left of centre, and may not solve the particular problem/s; it is of interest to this discussion. I have noticed that there are a few sites out there that allow files to go through, even though the file types are blocked in the “Antivirus/File Block” (only a v.small percentage). For example, the Antivirus/File Block of *.zip will block nearly all downloads of zip files, except from – www.netcomm.com.au (support downloads) Have also noticed this with phenomenon with *.exe from ato.gov.au, (this download has since been removed from the web site) In both cases the problem was resolved with a Antivirus/File Block of *.zip* and *.exe* In the Netcomm case, it uses some sort of php download function, and I tried to produce the same bypass problem in smtp, but could not replicate the problem (not enough time, or knowledge, or maybe it just works!) Tony, do all your blocked files come through?, if so then this would look like a individual firewall policy issue, or the position order of your particular smtp or http firewall policy and against some other policy that is letting the files through rob
    Contributor
    April 1, 2005
    Can you tell me what is the file size for the passthrough attachment? and what is the oversize limit in your fortigate? check from antivirus->config->config on GUI. van
    Contributor
    April 4, 2005
    Sorry, I was a few days off. Our problem with SMTP got solved (as it seems) by setting splice to the " wrong" status and then back to the " right" status to get rid of blocked attachments. Maybe it is just an coincidence ... Oliver
    Contributor
    April 4, 2005
    My issue was fixed too. It turns out in the Scan profile, I didn' t have the proper items checked. Fixed thanks to Fortinet support team. Thanks guys.