Hello
Looking for support to create rule(s) to stop uploading/leaking any file to any website or any where through internet. can allow 1MB file only, more than 1MB any file must be stopped leaking out.
1. even it must not allow to attach a file and save in draft email which is more than 1MB ( outlook email app/web attachment or any email)
2. when someone try to upload more than 1 MB i should store the detail of that file, user, IP, and target website as an DLP evidence.
3. thinking that, file size should be good option to limit , even when the targeted file embedded as an object in any other file.
4. It should also create logs for 1MB allowed files to investigate the data.
Please support..
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
Thank you for reaching out. There is way to block files by size by creating customizing the protocol options to block oversized files and set the size to the limi you want:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Blocking-large-files/ta-p/196069
Otherwise, I would recommend setting up the option in dlp and use the dlp sensor:
Thank you,
saleha
Hi Saleha,
I have tested it since many days but it is not stopping the leaking of data even through outlook. Looks like it has bugs to fix the DLP issues.
or any better way to do it ?
Hi @fortinetUser1,
What is the FortiOS version you are using? Do you have deep inspection enabled?
Regards,
v7.4.3
deep inspection enabled - Yes
If you are a staff of Fortinet , you may read details and history of open ticket # 9167826 on the DLP matter open since many weeks
Hi fortinetUser1,
This would require a deeper analysis and possible debug depending on your deployment. I recommend opening a ticket with TAC support if this is a product with a valid contract. Also it depends on what version of fortios this firewall has in case of the investigation direction leading to a bug therefore, if you have this fortigate on 7.0 FOS or earlier I recommend updating the firmware to 7.2 or 7.4 first. IF you went with deployment using dlp you can start troubleshooting the issue following the directions from the link below:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-DLP-Configuration-to-Block-File-s-and/ta-p...
Thank you,
saleha
Hi,
Thank you for the reply. I have checked the ticket briefly and I see Dev team being consulted. I recommend keeping the communication regarding this issue on the support ticket to avoid any misdirection also the support engineer working with you on this ticket has good grasp of the issue.
Thank you,
saleha
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.