Skip to main content
gquerenghi
New Member
February 5, 2016
Question

dlp is applied after whitelist check

  • February 5, 2016
  • 1 reply
  • 3296 views

I don't know if this is how it's supposed to work.

I set up dlp to block certain file types and whitelisted a domain in email filter, however mail coming from that domain with an attachment of that type is still blocked by dlp.

I updated the firmware to v5.2.5 and it still seems that dlp is running after white list check

    1 reply

    emnoc
    New Member
    February 6, 2016

    Did you run  diag debug flow  and what security profile do you have on the suspected fwpolicy?

     

    Last, have you  reviewed the life of the packet from fortinet?

    http://docs.fortinet.com/uploaded/files/2674/fortios-life-of-a-packet-524.pdf

     

    Take note of the section about web/dlp/app-control etc..... and flow vrs proxy