I don't know if this is how it's supposed to work.
I set up dlp to block certain file types and whitelisted a domain in email filter, however mail coming from that domain with an attachment of that type is still blocked by dlp.
I updated the firmware to v5.2.5 and it still seems that dlp is running after white list check
Did you run diag debug flow and what security profile do you have on the suspected fwpolicy?
Last, have you reviewed the life of the packet from fortinet?
http://docs.fortinet.com/uploaded/files/2674/fortios-life-of-a-packet-524.pdf
Take note of the section about web/dlp/app-control etc..... and flow vrs proxy
PCNSE
NSE
StrongSwan
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.