FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
abarushka
Staff
Staff
Article Id 337501
Description This article describes that the FortiGate DLP UTM profile is triggered by unexpected file type signatures while scanning Microsoft Office files.
Scope FortiGate.
Solution

Microsoft Office files (i.e. *.docx, *.xlsx, *.pptx) are .zip archives. The archive contains multiple folders and files (for instance *.xml, *.jpeg file types). This can be verified by opening a Microsoft Office file with an archive application. The following is an example of an unzipped .docx file:

 

123.JPG

 

FortiGate will extract the contents of the Microsoft Office file archive and inspect all folders and files. Consequently, a Microsoft Office file can trigger a DLP signature (for example, *.xml) other than the Microsoft Office file extension (for example, *.docx), since a *.docx archive file can contain *.xml files.