FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
kdharan
Staff
Staff
Article Id 347054
Description This article describes that it is not possible to create a DLP profile without the DLP sensor in the firewall GUI because it is a mandatory field in the GUI.
Scope FortiGate.
Solution

For certain configurations, the DLP profile should be configured without DLP sensors. The example scenario is to block the few/all file types with file size but not with the  'keywords or patterns' ( DLP Sensor).

 

For the example scenario, cannot add the  DLP Sensor to the DLP profile rules.

 

While trying to create the rule in the DLP Profile, getting the following error in the firewall GUI as shown below screenshot 

since the DLP sensor is one of the mandatory fields on the GUI.

 

DLP sesson error .png

 

To overcome this issue, configure the DLP profile using FortiGate CLI.

 

Refer to the below KB articles for the CLI configuration for the DLP configuration:

Technical Tip: How to block the 3mb file or larger file using DLP on the FortiGate
Technical Tip: Configure Data Leak/Loss Prevention (DLP)

 

 

Contributors