We tried to run 5.6.0 on one of transparent firewalls and it ended up blocking access for some users and coming up with data leak errors even if we had no DLP enabled in the policy. Has anybody else experienced anything like that with 5.6.0?
I have actually the same problem but running Proxy/NAT Mode with explicit proxy . Maybe it is the same actual scenario - I even have some users quarantined through DLP when they reach a certain treshold for some reason - most of them being "Blocked by Firewall-Policy" when I look into my threat dashboard, yet not nearly enough DLP events...
Is it the same on your end?
I have the same. The Fortigate put these hosts into quarantine. You may find them on "User Quarantine Monitor". - In My case the list entrys will expire in the past (Year 1936) !!! That looks like a bug.

But the reason is not clear. I never used "quarantine IP" into the DLP policy.
Same here. We never used the option "quarantine ip" in DLP, but have also the strange behaviour in DLP-Log in "DLP Extra" Column as it is described in this another post!
I upgraded my first firewall to 5.6 yesterday. This morning I had several computers quarantined because of DLP. I double-checked my config and I don't have any DLP rules set to quarantine. They are all set to log-only. I've had to remove the DLP rules for now.
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2678 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.