Created on
04-16-2025
04:35 AM
Edited on
07-07-2025
01:16 AM
By
Anthony_E
Description | This article describes a specific use case for blocking all file uploads through a web browser using FortiGate. |
Scope | FortiGate. |
Solution |
Blocking all types of file uploads through a web browser on FortiGate can be achieved by using a combination of Application Control and a custom signature configured to detect and prevent file upload activity.
In most cases, blocking all HTTP uploads is not fully achievable.
Define a signature pattern that detects characteristics commonly associated with file uploads, such as patterns in HTTP headers related to file transfer activity.
Configure the application control profile: In the 'General' settings, create or modify an application control profile. Include the previously created custom signature within the profile.
Apply the application control profile in a security policy: Go to 'Policy & Objects' and choose the relevant security policy for the targeted traffic.
Configure categories and actions according to specific requirements, with particular focus on categories associated with file uploads, such as 'File Sharing' or 'Cloud Storage'.
Access 'Policy & Objects' and select the security policy relevant to the traffic being managed. Edit the policy and, in the 'Security Profile' section, apply the configured web filter profile.
Note: Use firewall policy inspection-mode in the proxy.
Create a new DLP profile: Go to 'Policy & Objects' and choose the appropriate security policy for the targeted traffic. Edit the policy and, in the 'Security Profile' section, apply the configured DLP profile. Verify the DLP actions to ensure correct handling of detected file uploads.
Technical Tip: Block upload or download of PDF files larger than a specific size using DLP Technical Tip: DLP Configuration to Block by file-type and Troubleshooting |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.