Question
Blocking MIME or " content types" in HTTP
Hi, I am currently evaluating a Fortigate 100A and if successful, acquiring a 1000A. I have come from the Watchguard space and am looking for features in the Fortigate device. I am trying to block content types in HTTP for example video/x-flv, rather than use category based web filtering. As most of you are aware, category based web filtering does not filter content if it doesn' t fall into the category, meaning content which you have a policy on can get allowed. On the Watchguards you can set the allowed content types for the HTTP proxy. I am unable to find this option on the Fortigate. I have had a couple of ideas while trialling the unit - - Adding the string to Web Filter>Content Block, however this yields unwanted results. For example, if you add video/x-flv, it will block the entire page rather than the video object. Also if the page contains the string, obviously it is blocked regardless of it containing video or not eg, http://en.wikipedia.org/wiki/Flash_Video - Creating a custom IPS signature. This method i believe should work, however i see this as being an overly complex way of blocking content. The next issue is I don' t quite understand how one write IPS signatures. I have read all the related documentation, yet fail to grasp the process. Should creating custom IPS signatures be the best method, it would be greatly appreciated if someone could post with a custom signature to block video/x-flv as an example for which i can base the rest of my filters. Thank you, Lachlan.
