Subject: Unable to block WhatsApp Web file uploads despite SSL Deep Inspection and Application Control
Description:
We are trying to block certain file types (PDF, EXE, BIN, ZIP, RAR, DOC, DOCX) uploaded via WhatsApp Web using FortiGate. We have applied the following configurations:
SSL Deep Inspection is enabled on the relevant firewall policy.
Custom Application Signatures for file types have been created and added to the Application Control profile.
All relevant ports (TCP/80, TCP/443, UDP/443) are included.
Logging is enabled.
Issue:
Despite the above configurations, WhatsApp Web file uploads are still allowed; blocked actions are not enforced.
Packet captures with diagnose sniffer fail to detect WhatsApp Web traffic by hostname, only by IP.
Attempts to create custom signatures for multiple file types (PDF, EXE, ZIP, etc.) either fail due to CLI errors or do not block files as expected.
QUIC protocol (UDP/443) seems to bypass Application Control unless disabled.
Objective / Request:
Guidance on the correct method to block or monitor specific file types uploaded via WhatsApp Web.
Verification if additional FortiGate settings (Deep Inspection, DLP, Antivirus) are required.
Advice on proper Application Signatures and configuration to effectively block the target file types while allowing images and videos to pass.
I believe QUIC is only inspected from versions 7.4.1 in deep-inspection.
I used to have that issue, Only disabling QUIC solved the matter.
QUIC was disabled from the browser and from FortiGate, but the files in WhatsApp Web are still not blocked; FortiGate cannot block a specific file even though deep-inspection is enabled.
I'd say to try and block QUIC using a firewall policy to check that it is indeed not the issue.
I blocked QUIC via firewall policy and via Application Control. Despite this, it still cannot block certain files.
But if you've blocked it using a firewall policy it shouldn't work at all.
If it does block everything, I think the fact that QUIC is not inspected in your version is the problem.
@Salem_Alhindwan You may refer to the following article to block QUIC , it lists multiple options that you may use, from policy to app ctrl, as suggested earlier I would recommend that you go with the policy, which in the article is Method 3 and let me know.
Also, may I know if this upload that is being done is from the web mode or the application.
Created on ‎10-29-2025 06:50 AM Edited on ‎10-29-2025 06:52 AM
Uploading files via WhatsApp Web
In Application Control
We have
WhatsApp_Web.Upload
WhatsApp_Web.Download
This works for me, but only for uploading and downloading files.
It doesn't work for specific file types. For example, I want to block PDF files from uploading, and I also want to block image files from uploading in WhatsApp Web.
Created on ‎10-29-2025 06:53 AM Edited on ‎10-29-2025 06:55 AM
@Salem_Alhindwan Pls give me time until tomorrow I will check and update you, pls share more information such as browser in which is being used ? version and if incognito is enabled ?
Just letting you know, the signature as such would block all file uploads, is your requirement such that you would like to block just few file types and allow the rest? can you confirm?
Yes, I want to allow some file types and block others. The browser I'm using is Google Chrome, and incognito mode isn't working.
I blocked QUIC in Application Control, via the firewall policy, and through the Google Chrome browser.
Technical Tip: How to block/disable QUIC
I followed the same steps in the link you sent me, but the problem persists. I still can't block a specific file via WhatsApp Web through the browser.
| User | Count |
|---|---|
| 2702 | |
| 1415 | |
| 810 | |
| 716 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.