Skip to main content
fortinetUser1
New Member
February 5, 2024
Question

Need rule(s) to stop uploading/leaking any file to any website or any where through internet

  • February 5, 2024
  • 7 replies
  • 2709 views

Hello 

Looking for support to create rule(s) to stop uploading/leaking any file to any website or any where through internet. can allow 1MB file only, more than 1MB any file must be stopped leaking out.

1. even it must not allow to attach a file and save in draft email which is more than 1MB ( outlook email app/web attachment or any email)

2. when someone try to upload more than 1 MB i should store the detail of that file, user, IP, and target website as an DLP evidence.

3. thinking that, file size should be good option to limit , even when the targeted file embedded as an object in any other file.

4. It should also create logs for 1MB allowed files to investigate the data.

Please support..

7 replies

saleha
Staff & Editor
Staff & Editor
February 5, 2024

Hello,

 

Thank you for reaching out. There is way to block files by size by creating customizing the protocol options to block oversized files and set the size to the limi you want:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Blocking-large-files/ta-p/196069

Otherwise, I would recommend setting up the option in dlp and use the dlp sensor:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-Data-Leak-Prevention-DLP/ta-p/196796

 

Thank you,

saleha

fortinetUser1
New Member
April 3, 2024

Hi Saleha,

I have tested it since many days but it is not stopping the leaking of data even through outlook. Looks like it has bugs to fix the DLP issues.

or any better way to do it ?

hbac
Staff
Staff
April 3, 2024

Hi @fortinetUser1,

 

What is the FortiOS version you are using? Do you have deep inspection enabled? 

 

Regards, 

fortinetUser1
New Member
April 3, 2024

v7.4.3

deep inspection enabled - Yes

saleha
Staff & Editor
Staff & Editor
April 3, 2024

Hi fortinetUser1,

This would require a deeper analysis and possible debug depending on your deployment. I recommend opening a ticket with TAC support if this is a product with a valid contract. Also it depends on what version of fortios this firewall has in case of the investigation direction leading to a bug therefore, if you have this fortigate on 7.0 FOS or earlier I recommend updating the firmware to 7.2 or 7.4 first. IF you went with deployment using dlp you can start troubleshooting the issue following the directions from the link below:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-DLP-Configuration-to-Block-File-s-and/ta-p/218034

 

Thank you,

saleha

saleha
Staff & Editor
Staff & Editor
April 3, 2024

Hi,

 

Thank you for the reply. I have checked the ticket briefly and I see Dev team being consulted. I recommend keeping the communication regarding this issue on the support ticket to avoid any misdirection also the support engineer working with you on this ticket has good grasp of the issue.

Thank you,

saleha

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!