Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
CAD
Contributor

Deny email with specific extens(.ace)

Hello,

i have FG200D , running firmware 5.2.8

 

I am looking for a way to block all incoming emails that have attachments with extension (.ace)

 

Thanks

 

3 REPLIES 3
SCSIraidGURU
Contributor

Profile - Content, you can add it. 

Johan_de_Koning
New Contributor

I think you should preferably block extensions on your Mail Exchanger appliance, why? for logging and archiving what is blocked.

If you still want to do it on Fortigate, you need to go to Security Profiles -> Data Leak Preventions and make a new profile with a SMTP block of filename extension and put that filter on the policy for inbound and/or outbound (what is preferable). 

I never tested this and like i said earlyer, why do this on firewall level, do it on mail exchanger level.

Luiz_Alberto_Camilo

Use this Kb => http://kb.fortinet.com/kb/documentLink.do?externalID=FD35108

On the "Test_file_filter" list, change to "Filename pattern" and add "*.ace"

Apply this DLP to the firewall rule that inspects your Exchange traffic on port 25 SMTP. 

That should be enough. 

Luiz Alberto Camilo NCT São Paulo www.nct.com.br NSE-5 Expert

Luiz Alberto Camilo NCT São Paulo www.nct.com.br NSE-5 Expert
Labels
Top Kudoed Authors