Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rajeev1963
New Contributor

Blocked exe download not allowing Microsoft security to update

Hi I have blocked exe file download, now Microsoft security is not able to update definition files in the LAN systems. How to exempt only exe files for definition.
3 REPLIES 3
Terry_FTNT
Staff
Staff

Hello, I tested this using Nvidia as my reference point and was able to make it work in 4.0 MR3 Patch 5. What I did was created a DLP rule to block exe file types and exe file patterns much like yourself. I then created a URL filter for the blocked page. The URL filter in my case was URL - us.download.nvidia.com <---being the page that the download is from Type - Regex Action - Exempt By exempting the site you are bypassing the Fortigates scanning and it will allow the site not to be inspected therefore being able to download the exe file. Hope this helps
Regards, Terry Fortinet TAC Americas 1-866-648-4638 https://support.fortinet.com/ http://docs.forticare.com/fgt.html
ede_pfau
SuperUser
SuperUser

@Terry The pattern type should be ' simple' or ' wildcard' , not ' regex' . By sheer coincidence your pattern matched but that may not be the case with other URLs. In a regex, the dot stands for ' any character' whereas you meant ' a dot' . For example, your pattern as a regex would exempt ' ustdownload.nvidia.com' as well.

Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Terry_FTNT
Staff
Staff

That is a good point that which I did overlook.
Regards, Terry Fortinet TAC Americas 1-866-648-4638 https://support.fortinet.com/ http://docs.forticare.com/fgt.html
Labels
Top Kudoed Authors