Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dawish
New Contributor

Is it possiable to block file transfer feature on Line PC client while retaining other function?

Hello guys, I'm a newbie in IT field.
I'm currently trying to setup policy on a FortiGate100E to block the use of Line PC client.

>>FortiOS v7.2.4 build1396(Feature)

Now I successfully block Line usage, but regarding the subject, I want to know if it's possiable to block file transmission on Line PC client without affecting text and voice messages.

I've tried to dissecting packets and setting app signatures, but can't made any progress.

 

Thanks for any reply and possible assistance.

1 Solution
Nchandan
Staff
Staff

Hi,

 

Blocking the file transfer feature in the Line PC client while retaining other functions can be challenging because it requires identifying and controlling specific aspects of Line's communication protocol. Line uses a variety of ports and protocols for different functionalities, and blocking file transfers while allowing text and voice messages might involve granular control.

  1. Identify File Transfer Ports and Protocols:

    • Analyze the Line PC client's network traffic to identify the ports and protocols used specifically for file transfers. This might involve network traffic analysis or checking Line's documentation.
  2. Create Separate Firewall Policies:

    • Create separate firewall policies for Line traffic based on the identified file transfer ports and protocols versus text and voice communication. FortiGate allows you to create policies based on specific criteria.
  3. Use Application Control:

    • FortiGate supports Application Control features. Create an application control profile that permits Line for text and voice communication while blocking the application's file transfer capabilities. This involves specifying the application signature associated with Line's file transfer.

It's important to note that the effectiveness of these measures may depend on the specific details of Line's protocol and how it handles different types of communication. Additionally, any configuration changes should be made with caution and should align with your organization's network usage policies.

View solution in original post

2 REPLIES 2
Nchandan
Staff
Staff

Hi,

 

Blocking the file transfer feature in the Line PC client while retaining other functions can be challenging because it requires identifying and controlling specific aspects of Line's communication protocol. Line uses a variety of ports and protocols for different functionalities, and blocking file transfers while allowing text and voice messages might involve granular control.

  1. Identify File Transfer Ports and Protocols:

    • Analyze the Line PC client's network traffic to identify the ports and protocols used specifically for file transfers. This might involve network traffic analysis or checking Line's documentation.
  2. Create Separate Firewall Policies:

    • Create separate firewall policies for Line traffic based on the identified file transfer ports and protocols versus text and voice communication. FortiGate allows you to create policies based on specific criteria.
  3. Use Application Control:

    • FortiGate supports Application Control features. Create an application control profile that permits Line for text and voice communication while blocking the application's file transfer capabilities. This involves specifying the application signature associated with Line's file transfer.

It's important to note that the effectiveness of these measures may depend on the specific details of Line's protocol and how it handles different types of communication. Additionally, any configuration changes should be made with caution and should align with your organization's network usage policies.

dawish

Thank you very much for detailed explanation of my question, it has been very beneficial to me.

It seems I've oversimplified things, and I now evaluating other control measures to achieve the goals.

 

Anyway, thanks again!

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors