Skip to main content
Nonexisent12
Explorer
July 21, 2026
Question

DLP EDM Template Issue

  • July 21, 2026
  • 6 replies
  • 177 views

Hello, I am working on deploying Data Loss Prevention through our Fortigates in our organization. So far it has worked pretty well, and I was beginning to look at using a EDM template of Medication names provided by the FDA so that we can use it as a possible match of uploaded PHI.

Currently I am running into a issue with the EDM template parameters, where it will not match against anything using the edm-keyword data type. Using a test CSV with a fake SSN, the ssn-us keyword does work, but nothing I try with edm-keyword works. I know that the file be checked against the DLP profile by checking the logs. I have tested this with dlptest.ai by Fortinet and also other sites we are wanting this DLP filter on. DLP works otherwise as well, the other rules I make are working, just not the EDM template in the way I want to use it. The Fortigate I am testing with is running 7.4.11, this is temporary though as we are working to move to 7.6.x as we move away from SSL VPN.

Am I missing something in the configuration, or is this a known issue with EDM? I have attached the current EDM template that I have, along with what the data looks like that I am trying to match against. Thank you, and please let me know if I need to give any other information. 

 

Med Test EDM Template
FDA List of Prescription Medications

 

6 replies

Stephen_G
Staff & Editor
Staff & Editor
July 24, 2026

Hi Nonexisent12,

Thanks for using Fortinet Community. We’ll look to get you an answer or help. In the meantime, if anyone else has any advice, feel free to respond.

 

Stephen_G - Fortinet Community Team
Stephen_G
Staff & Editor
Staff & Editor
July 28, 2026

Hi Nonexisent12,

 

We are still looking to get you an answer or help. Thank you for your patience. 

Stephen_G - Fortinet Community Team
pjang
Staff & Editor
Staff & Editor
July 30, 2026

Hi ​@Nonexisent12,

 

So I took a look at this since ​@Stephen_G forwarded the request our way. I was able to get this working in my lab (FortiGate-81F running 7.6.7), so you may have a misconfiguration somewhere that is preventing your setup from working, or there is some nuance here that is too deep to solve on a Support Forum (FortiGate model/version issue, some kind of DLP bug, some other circumstance related to your overall configuration that is somehow interacting with your DLP setup, etc.). I would recommend opening a ticket with TAC so you can get some deeper troubleshooting and review going, but in the meantime this is a checklist of what I needed to get this working:

 

  • Created an EDM Template (Security Profiles → Data Loss Prevention → EDM Template). I took the Excel version of the NDC database available for download here (https://www.fda.gov/drugs/drug-approvals-and-databases/national-drug-code-directory) and converted it into a .csv format with Excel.
    • I can’t load the ~40MB file onto my desktop FortiGate-81F due to external resource size restrictions (see here for more info), so I just took the first 6 rows as a basic test case and hosted the truncated .csv on an Nginx server I had available. In theory you should have no issues with using the full file containing ~115832 entries as long as you have a sufficiently large FortiGate model, and are note maxed out with other external resource lists, but I could not test that with the equipment I had available.
    • My EDM template matched yours, with Column Index 4 (“PROPRIETARYNAME” in this case) matching the edm-keyword Data Type.
  • Created a DLP Sensor (Security Profiles → Data Loss Prevention → Sensor). I created a new Sensor with a single new entry that referenced the EDM Template that I created above (found in the “Managed Locally” section).
  • Created a new DLP Profile (Security Profiles → Data Loss Prevention → Profile). I created a new DLP profile that referenced the earlier Sensor as a match Rule. In this case I kept it simple and blocked any matches that used HTTP-POST:
  • Applied the DLP Profile to a Firewall Policy with Proxy-based inspection and SSL Deep Inspection. Nothing much to say here.
  • Tested by visiting dlptest.ai and used the “Text upload to website” option from a Windows test VM

 

Nonexisent12
Explorer
August 11, 2026

The difference here is that you used g-edm-keyword, while I used just edm-keyword. From what I know, I am not a expert, g- means it is flow based rather than proxy. I will try to see if I can use that instead and will get back to you, thank you for the thorough answer.

“No pride for some of us without liberation for all of us.” -Marsha P. Johnson
Nonexisent12
Explorer
August 11, 2026

Ok so, I did just test it now, g-edm-keyword is not available in the fortigate that I am using. Still, I tested it with a flow based policy rule instead, no change for me. I will hold off on this until we are able to setup 7.6.7, and if it still doesn’t work I will contact the support you mentioned.

“No pride for some of us without liberation for all of us.” -Marsha P. Johnson
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!