Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Prevent filedownload with DLP at SAMBA/CIFS connections ?

Hi, i´m wondering if it is possible to prevent to download/copy files by a smb/cifs connection over SSL-VPN. I want to prevent users connected by SSL-VPN to download files from our Fileserver The files we don´t want to share over the SSL-VPN are AutoCAD (*.dwg) files. Is it possible to prevent this by setting a DLP rule or is this just possible over common protocols like HTTP or FTP? thx Ps. we are using a Fortigate 80c with v4.0,build0441,110318 (MR3)
2 REPLIES 2
romanr
Valued Contributor

There is no inspection in the CIFS or SMB protocol in FortiOS right now. AFAIK there were plans and prototypes in the OS 4 devel process to build protocol decoding mainly for AV for CIFS... There must have been bigger technical issues around that, therefore they dropped it... Maybe because of the many standards/dialects of SMB and CIFS that are out there in the world... best regards, Roman
lmuir
New Contributor

You could probably do it with IPS.
Labels
Top Kudoed Authors