Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
User_02
New Contributor

EXE files in ZIP archives

Hello, is it possible to block Mails with an attached ZIP file that contains a file with an EXE extension?

I am using a FGT100D with v4.00 MR3 Patch 18.

 

thanks and best Regards

11 REPLIES 11
Iescudero
Contributor II

Hi! With DLP you can block that kind of files, you only need to create a DLP Rule, put in  Sensor and add that sensor in the Firewall policy.

User_02
New Contributor

Thank you, but it doesent work.

Now i cant Download .exe files, but i can still download zip files that contains .exe files.

 

 

Iescudero

I assumed using the email with some smtp client like outlook. If so, the policy has to be between clients and the mail server port 25 (smtp service) and port 110 (pop3 service) for full suction of emails. If you use in service emails through web, such as hotmail, gmail or yahoo, the option to use APPLICATION control would be an example to deny uploaded by HTTP or HTTP downloading any files from emails. If you can detail what your topology, or the best changes you applied.

Regards

User_02

we use Exchange and download the EMails with POPcon for Exchange over port 995 pop3ssl. Exchange send the mails via port 25.

 

In the fortigate configuration i have made the following settings:

Data Leak Prevention -> File Filter -> all_executables -> File Types -> bat, exe, elf, hta -> Block and Enabled Edit DLP Sensor -> New -> Create New -> Filter by "File Type" -> File Pattern "all_executables" -> Action "Block" -> Archive "Summary Only" in the Policy i have enabled the DLP Sensor

Iescudero

Ok, and now, what exactly is not working? does not block the exe files?

User_02

exe files are blocked, but not the zip files that contains the exe files.

Iescudero

Try to add to the sensor a new rule but instead select file type, select file pattern and set *.exe like name.

And tell me if it works.

 

byes!

User_02

i cant add file pattern to the sensor. Only "Fingerprint", "File Type", "File Size", "Regular Expression", "Advanced Rule" and "Compound Rule" are available in the field filter by. I can add "File Pattern" to the File Filter, but it doesent work for zip files.

TuncayBAS
Contributor II

in used firewall profil-protection-options following settings.

 

set scan-bzip2 enable

set uncompressed-nest-limit 2

 

 

Tuncay BAS
RZK Muhendislik Turkey
FCA,FCP,FCF,FCSS
Tuncay BASRZK Muhendislik TurkeyFCA,FCP,FCF,FCSS
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors