Hello, is it possible to block Mails with an attached ZIP file that contains a file with an EXE extension?
I am using a FGT100D with v4.00 MR3 Patch 18.
thanks and best Regards
Hi! With DLP you can block that kind of files, you only need to create a DLP Rule, put in Sensor and add that sensor in the Firewall policy.
Thank you, but it doesent work.
Now i cant Download .exe files, but i can still download zip files that contains .exe files.
I assumed using the email with some smtp client like outlook. If so, the policy has to be between clients and the mail server port 25 (smtp service) and port 110 (pop3 service) for full suction of emails. If you use in service emails through web, such as hotmail, gmail or yahoo, the option to use APPLICATION control would be an example to deny uploaded by HTTP or HTTP downloading any files from emails. If you can detail what your topology, or the best changes you applied.
Regards
we use Exchange and download the EMails with POPcon for Exchange over port 995 pop3ssl. Exchange send the mails via port 25.
In the fortigate configuration i have made the following settings:
Data Leak Prevention -> File Filter -> all_executables -> File Types -> bat, exe, elf, hta -> Block and Enabled Edit DLP Sensor -> New -> Create New -> Filter by "File Type" -> File Pattern "all_executables" -> Action "Block" -> Archive "Summary Only" in the Policy i have enabled the DLP Sensor
Ok, and now, what exactly is not working? does not block the exe files?
exe files are blocked, but not the zip files that contains the exe files.
Try to add to the sensor a new rule but instead select file type, select file pattern and set *.exe like name.
And tell me if it works.
byes!
i cant add file pattern to the sensor. Only "Fingerprint", "File Type", "File Size", "Regular Expression", "Advanced Rule" and "Compound Rule" are available in the field filter by. I can add "File Pattern" to the File Filter, but it doesent work for zip files.
in used firewall profil-protection-options following settings.
set scan-bzip2 enable
set uncompressed-nest-limit 2
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.