Skip to main content
kyle-hsuan
Explorer
May 6, 2026
Question

how to block ftp upload or download

  • May 6, 2026
  • 3 replies
  • 105 views

Hi

 

I try to configure firewall policy service select FTP_GET or FTP_PUT

but it doesn’t work

3 replies

Anthony_E
Staff
Staff
May 6, 2026
Talank
Staff
Staff
May 7, 2026

Hello ​@kyle-hsuan ,

 

Adding to ​@Anthony_E comment’s, You can also block specific file type using DLS,

 

A DLP file pattern can block, allow, log, or quarantine a file based on the specified file type in the file filter list (see Supported file types below).

https://docs.fortinet.com/document/fortigate/7.4.8/administration-guide/610893/supported-file-types

You can also use file filter as below to configure.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-block-a-file-based-on-a-pattern-using-DLP/ta-p/254726
 

msanjaypadma
Staff
Staff
May 7, 2026

Hi ​@kyle-hsuan ,

It is advisable to verify the port number on which the remote FTP service is listening. 

Please perform a packet capture directed at the destination FTP server's IP address to determine this information. 

On FortiGate CLI command : 

 
#diagnose sniffer packet any “host x.x.x.x​” 4 0 a

where x.x.x.x replace with FTP server ip address. 


Once the port number is identified, you can create a policy that specifies the destination server IP address and service port, and configure the action to deny access accordingly.

If you have found a solution, please like and mark it as solved to make it easily accessible for everyone.
 

Thanks,
Mayur Padma 

Thanks, Mayur Padma
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!