Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Kevin_Noble
New Contributor

Anybody having trouble with Data Leak errors with 5.6.0

We tried to run 5.6.0 on one of transparent firewalls and it ended up blocking access for some users and coming up with data leak errors even if we had no DLP enabled in the policy.  Has anybody else experienced anything like that with 5.6.0?

4 REPLIES 4
GoDannY
New Contributor

I have actually the same problem but running Proxy/NAT Mode with explicit proxy . Maybe it is the same actual scenario - I even have some users quarantined through DLP when they reach a certain treshold for some reason - most of them being "Blocked by Firewall-Policy" when I look into my threat dashboard, yet not nearly enough DLP events...

 

Is it the same on your end?

 

renedubs

I have the same. The Fortigate put these hosts into quarantine. You may find them on "User Quarantine Monitor". - In My case the list entrys will expire in the past (Year 1936) !!! That looks like a bug.

 

But the reason is not clear. I never used "quarantine IP" into the DLP policy.

dpaech

Same here. We never used the option "quarantine ip" in DLP, but have also the strange behaviour in DLP-Log in "DLP Extra" Column as it is described in this another post!

MattM
New Contributor

I upgraded my first firewall to 5.6 yesterday.  This morning I  had several computers quarantined because of DLP.  I double-checked my config and I don't have any DLP rules set to quarantine.   They are all set to log-only.  I've had to remove the DLP rules for now.  

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors