| Description | This article describes how to Block all file types with more than 3MB files or larger files using DLP on the FortiGate. |
| Scope | FortiOS and FortiProxy, |
| Solution |
Block the 3MB file or larger file using the DLP.
DLP profile configuration for versions 7.2.4 and above:
config dlp profile set action block
Note: SSL inspection should be a deep inspection. and file type is part of the executable files listed. For example, using the default file pattern 'all_executalbles' which block listed block files '.bat, .exe, .elf, .hat' file types.
To check the file types used in the profile as shown below (it is possible to add or remove the other file types in it).
config dlp file pattern
Note: For versions between 6.2.2 and 7.2.3, the CLI commands are a bit different. DLP profile is configured as 'config dlp sensor' and 'config rule' is changed to 'config filter'. To get more information, review this article.
Related article: Technical Tip: DLP Configuration to Block File's and Troubleshooting |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.