Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fortinetUser1
New Contributor

Need rule(s) to stop uploading/leaking any file to any website or any where through internet

Hello 

Looking for support to create rule(s) to stop uploading/leaking any file to any website or any where through internet. can allow 1MB file only, more than 1MB any file must be stopped leaking out.

1. even it must not allow to attach a file and save in draft email which is more than 1MB ( outlook email app/web attachment or any email)

2. when someone try to upload more than 1 MB i should store the detail of that file, user, IP, and target website as an DLP evidence.

3. thinking that, file size should be good option to limit , even when the targeted file embedded as an object in any other file.

4. It should also create logs for 1MB allowed files to investigate the data.

Please support..

7 REPLIES 7
saleha
Staff
Staff

Hello,

 

Thank you for reaching out. There is way to block files by size by creating customizing the protocol options to block oversized files and set the size to the limi you want:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Blocking-large-files/ta-p/196069

Otherwise, I would recommend setting up the option in dlp and use the dlp sensor:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-Data-Leak-Prevention-DLP/ta-p/19...

 

Thank you,

saleha

fortinetUser1
New Contributor

Hi Saleha,

I have tested it since many days but it is not stopping the leaking of data even through outlook. Looks like it has bugs to fix the DLP issues.

or any better way to do it ?

hbac

Hi @fortinetUser1,

 

What is the FortiOS version you are using? Do you have deep inspection enabled? 

 

Regards, 

fortinetUser1

v7.4.3

deep inspection enabled - Yes

fortinetUser1

If you are a staff of Fortinet , you may read details and history of open ticket # 9167826 on the DLP matter open since many weeks 

 

saleha
Staff
Staff

Hi fortinetUser1,

This would require a deeper analysis and possible debug depending on your deployment. I recommend opening a ticket with TAC support if this is a product with a valid contract. Also it depends on what version of fortios this firewall has in case of the investigation direction leading to a bug therefore, if you have this fortigate on 7.0 FOS or earlier I recommend updating the firmware to 7.2 or 7.4 first. IF you went with deployment using dlp you can start troubleshooting the issue following the directions from the link below:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-DLP-Configuration-to-Block-File-s-and/ta-p...

 

Thank you,

saleha

saleha
Staff
Staff

Hi,

 

Thank you for the reply. I have checked the ticket briefly and I see Dev team being consulted. I recommend keeping the communication regarding this issue on the support ticket to avoid any misdirection also the support engineer working with you on this ticket has good grasp of the issue.

Thank you,

saleha

Labels
Top Kudoed Authors