Created on
08-06-2024
04:10 PM
Edited on
05-14-2025
04:48 AM
By
Jean-Philippe_P
Description | The article describes that DLP profile does not work as expected for the CCN body message if the Outlook desktop app sends traffic using HTTPS protocol. |
Scope | Any FortiOS. |
Solution |
Configure Outlook to use MAPI over HTTP or RPC over HTTP protocols and ensure that the data transferred is not exclusively over HTTPS. The FortiGate needs to have MAPI-over-HTTP enabled in the SSL inspection profile:
config firewall ssl-ssh-profile
It has been confirmed that a functional version of the Outlook desktop app is Version 2405, Build 16.0.17628.20006. Newer versions do not support the MAPI protocol for traffic from the Outlook desktop app.
diagnose debug reset diagnose sys scanunit debug all diagnose debug enable
Execute the WAD debugs:
diagnose wad debug enable category all diagnose wad debug enable cate http
Repeat the steps mentioned above from 1 to 3.
If needed, open a TAC ticket to get help interpreting the collected debug information. Reach Microsoft support to get additional assistance on how to configure the recent Outlook desktop app if it is possible. |
Great article thank you @gonzalezw
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.