This article describes how to use file filters for detecting or blocking files sent or received via https. The solution stated below can also apply for encrypted protocols such as MAPI, SSH, and IMAP over SSL/TLS.
FortiGate v6.4 and above.
To use a file filter to detect files sent or received via HTTPS, a proxy mode file filter is required, along with a deep-inspection SSL/SSH profile.
If the Feature set option is not visible in the GUI, enter the following in the CLI:
config system settings
set gui-proxy-inspection enable
end
Note:
Related article:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.