Skip to main content
Intranetworks
New Member
December 29, 2016
Question

DLP with Web Filter

  • December 29, 2016
  • 1 reply
  • 4086 views

Hi,

We have made some IPV4 policies over FortiGate 51E running fortiOS v5.4.2,build1100 (GA) version. We are using FSSO to authenticate users that have specific web filter categories and we are trying to deploy DLP with some user exceptions but without success. Our main goal is to block executables files for users that does not belong to AD group called “GRP-ALLOW-EXECS”. At the same time, we have 3 other groups for web filtering: GRP-RESTRICTED-WEB, GRP-MODERATE-WEB and GRP-PRIVILEGED-WEB (for different web filter policies respectively). For all 3 web filter policy we have set DLP to block executable downloads and that’s OK but if we create a new policy rule above to allow exec downloads for the AD group, the webfilter policies (below) are bypassed.

 

Is there a way to combine WebFilter and DLP profiles together?

    1 reply

    Johan_de_Koning
    New Member
    May 2, 2017

    Sorry to say but what you are saying doesnt make sense since this is expected behaviour, ofcourse is the rule which is on top of the chain will prevail the others being under it. Classis Firewall behaviour.

     

    So to think in the perspective in which you will succeed is, place group GRP-ALLOW-EXECS with its DLP filter for blocking execs on top of the 3 groups GRP-RESTRICTED-WEB, GRP-MODERATE-WEB and GRP-PRIVILEGED-WEB. The 3 groups will then still be blocked with execs according to your policy. 

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.