Stats:
-Fortigate with 5.4.4 firmware
-DLP policy enabled, configured to block certain files
-SSL "full inspection" enabled. no category exemptions, no address exemptions for dropbox.com, reputable websites is disabled. Fortigate certificate installed on client machines, and appears in the browser when viewing dropbox.com.
-Proxy option Default policy enabled
When uploading a certain blocked file, DLP fails to block with Dropbox's "enhanced uploader." If I use the dropbox "basic uploader" the files is blocked with a DLP message from Fortigate.
Why could DLP be failing with the enhanced uploader?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Further testing seems to indicate this is a problem specifically with "File Name Patterns" on the DLP policy. Why?
Is it possible the file is getting broken up and transferred through multiple connections (like google QUIC)? That might hide a filename and make other pattern matching difficult. I don't know if dropbox using HTTP/2 multiplexing for some things could be part of this.
Also, are you doing SSL deep inspection on all ports? Perhaps the enhanced uploader is just using non-standard ports? My understanding was that Dropbox only used HTTP and HTTPS, except for LAN sync, but that may no longer be the case.
Do let us know what you find. I've had to block QUIC and TEREDO on some subnets to allow full SSL inspection. Would be good to know if there is something else I need to work around as well.
Hello JohnGeorge,
I tested DLP + deep-inspection with Enhanced Uploader and I am able to block the files. From my traffic analysis, Dropbox does not appear to use QUIC protocol. I left "File Name Patterns" empty though. Looking at the plaintext HTTP headers, they look like standard headers that a regular string search should be able to easily detect.
Can you give me more information on the "File Name Patterns" you used and I can check on my side? Thanks!
HoMing
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.