FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
tino_p
Staff
Staff
Article Id 242579
Description This article describes how to block file transfer in Skype while allowing chats/texts.
Scope FortiGate version 7.2.
Solution
  1. Create a new application profile. Depending on the business operation, it is possible to block all default FortiGuard categories or monitor/allow/quarantine the desired ones.

 

tino_p_0-1673405786773.png

 

In Application and Filter overrides, create a filter to block 'Skype_File'. Transfer (it is required to use Deep Inspection in Firewall policy), a filter to allow all other Skype signatures, and SSL. 

 

tino_p_2-1673407016352.png

 

  1. Create a firewall policy to allow traffic from LAN to WAN, with the above application profile and Deep inspection.

     

    tino_p_3-1673407141396.png

     

     

  2. Test on the client side, it is possible to see the file cannot be transferred, however, the texts/chat still is processed normally.

     

    tino_p_4-1673407507911.png

     

     

  3. Block results also show up in FortiGate -> Log&Report -> Application Control.

     

    tino_p_5-1673407611818.png

     

    Note: in 1., if the SSL is not allowed, the Skype application will show blank when trying to log in like this:

     

    tino_p_1-1673406953916.png