Created on
02-10-2025
02:53 AM
Edited on
09-08-2025
12:35 AM
By
Jean-Philippe_P
This article describes how to configure the File Filter to allow/block file types for emails like Gmail or Outlook.
FortiGate v7.2.5 or above.
Note:
Outlook uses the MAPI over HTTPS protocol, so MAPI over HTTPS inspection must be enabled in the SSL/SSH inspection profile when Outlook is used as the email client.
To enable MAPI over HTTPS inspection in CLI, use the following command:
config firewall ssl-ssh profile
edit "your_profile"
set mapi-over-https enable <---
next
end
In GUI and CLI, run the following command line to check file filter logs:
execute log filter category utm-file-filter
execute log display
Note:
Use Proxy Inspection Mode on both Policy and File Filter Profile, add Customs deep-inspection mode, and install the certificate on the user PC under the Trusted Rooted certificate. It is now blocking the files from Gmail.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.