Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ITCSS
New Contributor II

Microsoft Autopilot won't work - Intune - DLP and .cab

Hi,

I've been reading and tweaking the firewall policy rule to no avail.

  • Made IP lists from official Microsoft web page.
  • Allowed website and application from their official website.
  • Tried with and without SSL Inspection
  • The policy is put above almost everything else and nothing affect the IP subnet range

Autopilot won't work (often when choosing Office/365)

  • Nothing is being blocked in FortiAnalyzer except for a few .cab
  • We're thinking it might be linked to the .cab issue:
    • The DLP is still blocking some .cab
      • authrootstl.cab
      • disallowedcertstl.cab
      • pinrulesstl.cab
        • Even if the DLP HTTP-Get is activated or not
        • Even if the file filter for .cab is activated or not.
              Threat :Action: blocked
              Threat Direction: incoming
              Threat Name:data leak by Filter: none
              Threat Pattern: disallowedcertstl.cab
              Threat Severity: low
              Threat Type:Data Leak

          Any help appreciated.

          Thank you for your time.
Best regards,
Best regards,
4 REPLIES 4
sjoshi
Staff
Staff

Hi ITCSS,

 

Are you using FGT DLP feature to block certain files types.

Please refer

https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/153498/data-loss-prevention

Let us know if this helps.
Salon Raj Joshi
ITCSS
New Contributor II

Hi @sjoshi ,

 

To monitor and allow .cab

DLP-FF.png

Best regards,
Best regards,
ITCSS
New Contributor II

Some .cabs seems to pass now. I'm not seeing anything blocking in the FortiAnalyzer. It didn't seem to work yesterday evening but I'm waiting for a new test.

 

I'm going to keep you updated

Best regards,
Best regards,
ITCSS
New Contributor II

New .cabs being blocked -

Threat Action: blocked
Threat Direction: incoming
Threat Name: data leak by Filter: none
Threat Pattern: Microsoft.VCLibs.120.00.UWPDesktop_12.0.40653.0_x64__8wekyb3d8bbwe.Appx
Threat Severity:low
Threat Type:Data Leak

 

Why is there a filter:none ?

 

Also there's no .appx to choose from in the File Filter.

 

Edit: Still have that message even with "unset dlp-sensor" in CLI

Best regards,
Best regards,
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors