| Description | This article describes how to allow Excel .xlsx file when Block File Type Validation is used in File Protection. |
| Scope | FortiWeb-Cloud, SaaS Platform. |
| Solution |
When Block type is used in File Protection, file type must be explicitly allowed in File Type Validation. There are cases where Excel .xlsx has been unselected from the Block list but the user is unable to upload the .xlsx file type and it triggers a File Protection attack log.
Attack Log:
File Protection Configuration:
This is due to Excel being a compressed XML file that would be identified as a zip file by File Protection. To allow Excel .xlsx file, unselect 'ZIP' from the Block list, and the .xlsx file upload should be allowed.
For more information about File Protection, refer to the FortiWeb-Cloud Administration guide: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.