FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
KC_Hing
Staff
Staff
Article Id 219694
Description

This article describes how to deny uploading images, documents, or videos in WhatsApp web conversation by using the application control signature.

Scope

FortiGate.

Solution

To control web WhatsApp upload traffic would require enabling SSL deep inspection + application control profile in the firewall policy.

 

  1. Go to Security Profiles -> Application Control, select 'Profile Name' and select 'Edit'.

  2. Inside the profile, go to Application and Filter Overrides, and select 'Create New'.

  3. Go to Action Block and Search for the application signature: WhatsApp_Web_File.Upload, right mouse button, and + Add Selected. 

 

KC_Hing_0-1659595155443.png

 

 

An alternative way is by adding both signatures WhatsApp_Web_File.Upload and WhatsApp_Web_File.Download.

 

This will block any file that a user wants to download using the same application control profile.

 

                                                                     image.png

  

  1. Enable the 'QUIC' protocol option with an action block.
                        

    KC_Hing_1-1659595254418.png

     

     

  2. Use the application control profile in the firewall policy with SSL deep inspection.  

     

    KC_Hing_2-1659595308204.png

     

     

  3. Test the file transfer with a desired file or photo.

     

    jordancueay1_0-1724802002343.png

     

The photo was successfully blocked. The exclamation mark at the right indicates that the image could not be transferred. 

 

Be informed that previously uploaded files are stored in the chat history/cache so attempts of sending the same file will not be treated as an upload. The configured signature blocks all new upload attempts.

 

Related documents:

APP Control

Technical Tip: How to enable deep inspection and import a certificate in the browser