Skip to main content
Dipen
New Member
September 7, 2014
Question

DLP with HTTPS

  • September 7, 2014
  • 13 replies
  • 19164 views
We have created a DLP Filter to block EXE Files. It is working with HTTP Sites however download of exe' s still happening from HTTPS Sites. Same issue like WebFilter.

    13 replies

    Adeel
    New Member
    December 10, 2014

    Dear Fellows ,

     

    I have seen all above post I would like to ask you how to configure DLP for https enable website I mean if whoever want to try to upload company data on https enable website then fortigate generate the logs well i have tried with SSL DEEP INSPECTION but it does not work please assist me what should i do ? Normal http websites are working fine .

     

    -Fortigate 100D version 5

    Adrian_Buckley_FTNT
    Staff
    Staff
    December 10, 2014

    The FortiGate 100D supports SSL Deep inspection.  So for starters you will need to enable that.  Have you done so?

     

    Also, Firmware version 5 is not specific enough.  What MR and patch?

    Adeel
    New Member
    December 11, 2014

    Dear Adrian ,

     

    Thank you for reply mentioned below is fortigate system status if this is supported please send me the configuration steps for https with DLP basically my task is if anyone try to upload any kind of company file like word,pdf and xls etc it should be monitored kindly send me step by step configuration steps thank you.

     

    Fortigate $ get system status

    Version: FortiGate-100D v5.0,build0271,140124 (GA Patch 6)

    Virus-DB: 23.00365(2014-12-10 12:11)

    Extended DB: 21.00575(2014-02-04 20:03)

    IPS-DB: 5.00583(2014-12-09 00:55)

    IPS-ETDB: 0.00000(2001-01-01 00:00)

    Serial-Number: FG100D

    Botnet DB: 1.00379(2014-02-05 10:45)

    BIOS version: 04000030

    xxxxxxxxxxxx

    Log hard disk: Available

    Internal Switch mode: interface

    Hostname: fortigate

    Operation Mode: NAT

    Current virtual domain: Browse

    Max number of virtual domains: 10

    Virtual domains status: 2 in NAT mode, 2 in TP mode

    Virtual domain configuration: enable

    FIPS-CC mode: disable

    Current HA mode: a-p, master

    Branch point: 271

    Release Version Information: GA Patch 6

    FortiOS x86-64: Yes

    System time: Thu Dec 11 10:31:18 2014