Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
pottapitot
New Contributor

VPN - Prevent copying between connected systems

Hi,

We are using Fortigate 300c. Currently, users can copy data from the system they are connecting from (home computer) to the system they are connecting to (corporate system) and vice versa . Is it possible to disable this functionality for specific users or portals (including clipboard)?

 

I am sure but I heard there was also another feature that creates a temporary workspace and clears the same when VPN is disconnected. How does that work and will that help here (if it is present)?

 

I am trying to prevent possible malware transfer and DLP with this method.

 

Thanks in advance.

7 REPLIES 7
scerazy
New Contributor III

Of course, you seems to have NO service filtering in your SSL Policy

Just set it up & users can only connect to what you allow them to

 

pottapitot

Thanks for the response scerazy. From our end we have enabled only RDP. The user is still able to copy files to and from the connected system and the host system. The Fortigate version we are using is 5.2.6.

 

scerazy
New Contributor III

Then there must be some OTHER policy that allows it!

This policy (as you see above, allows ONLY the specified service! - there is no magic to it

 

But what do you mean copy? Using Windows Explorer OR RDP mapped drives?

If the later then disable this funcionality!

 

Seb

emnoc
Esteemed Contributor III

Check  via cli cmd "diag debug flow" to find the fwpolicy that allows for the unintended function and then 1> modify it or 2> add a correct fwpolicy.

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
netmin
Contributor II

It doesn't sound like a firewall issue. I would suggest to review the group policies, especially 'device and resource redirection' capabilities: https://technet.microsoft.com/en-us/library/ee791756%28v=ws.10%29.aspx

 

 

Alexis_G

Block copy paste from RDP server

https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/ee...

--------------------------------------------

If all else fails, use the force !

-------------------------------------------- If all else fails, use the force !
rwpatterson
Valued Contributor III

As jklapas stated, this is a Windows issue. Files are copied and pasted over the RDP protocol, so unless there is some granular sniffing of the traffic, there is likely no way the Fortigate will ever know what is being transferred over the connection.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors