FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
abarushka
Staff
Staff
Article Id 337501
Description Fortigate DLP UTM profile is triggered by unexpected file type signature while scanning Microsoft office files
Scope FortiGate.
Solution

Microsoft office files (i.e. *.docx, *.xlsx, *.pptx) are .zip archives. The archive contains multiple folders and files. This can be verified by opening a Microsoft office file with an archive application. The following is an example of an unzipped .docx file:

 

123.JPG

 

FortiGate will extract the contents of the Microsoft office file archive and inspect all files. Consequently, Microsoft office file can trigger a DLP signature (for example, *.xml) other than the Microsoft office file extension (for example, *.docx), since a *.docx archive file can contain .xml files.