Subject: Unable to block WhatsApp Web file uploads despite SSL Deep Inspection and Application Control
Description:
We are trying to block certain file types (PDF, EXE, BIN, ZIP, RAR, DOC, DOCX) uploaded via WhatsApp Web using FortiGate. We have applied the following configurations:
SSL Deep Inspection is enabled on the relevant firewall policy.
Custom Application Signatures for file types have been created and added to the Application Control profile.
All relevant ports (TCP/80, TCP/443, UDP/443) are included.
Logging is enabled.
Issue:
Despite the above configurations, WhatsApp Web file uploads are still allowed; blocked actions are not enforced.
Packet captures with diagnose sniffer fail to detect WhatsApp Web traffic by hostname, only by IP.
Attempts to create custom signatures for multiple file types (PDF, EXE, ZIP, etc.) either fail due to CLI errors or do not block files as expected.
QUIC protocol (UDP/443) seems to bypass Application Control unless disabled.
Objective / Request:
Guidance on the correct method to block or monitor specific file types uploaded via WhatsApp Web.
Verification if additional FortiGate settings (Deep Inspection, DLP, Antivirus) are required.
Advice on proper Application Signatures and configuration to effectively block the target file types while allowing images and videos to pass.
The problem hasn't been solved yet. Does anyone have any idea what the problem is?
Created on ‎11-01-2025 08:38 PM Edited on ‎11-01-2025 08:40 PM
@Salem_Alhindwan Apologies for the delay, the requirement to have certain specific file type might not work cause based on my research on this, WhatsApp encrypts the payload (files) prior to them being uploaded on to their servers, so even though you may have deep inspection enabled, the details of the file itself would not be visible since it has been encrypted locally and then being uploaded.
As such the option available would be to use application control signature, to block file uploads, but again this will block all file uploads and not specific file types, like what you are looking for.
Hope this helps!!!
| User | Count |
|---|---|
| 2735 | |
| 1417 | |
| 812 | |
| 739 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.