Helpful ReplyHot!DLP GUI option gone in 6.2.2

Author
ianmclachlan
New Member
  • Total Posts : 7
  • Scores: 0
  • Reward points: 0
  • Joined: 2019/03/01 01:47:24
  • Status: offline
2019/11/04 08:00:25 (permalink)
0

DLP GUI option gone in 6.2.2

Hi Guys,
 
Have noticed that the GUI DLP configuration page is missing from 6.2.2.  I can, of course use the CLI, however, I'm lazy and prefer point and click.  Does anyone know if it's buried deep in the system somewhere?
 
Thanks
#1
tioeudes
Bronze Member
  • Total Posts : 29
  • Scores: 4
  • Reward points: 0
  • Joined: 2019/10/22 09:47:38
  • Status: offline
Re: DLP GUI option gone in 6.2.2 2019/11/04 08:24:13 (permalink)
0
Don't you have to enable the feature under Feature Visibility?
 
 
 
#2
ianmclachlan
New Member
  • Total Posts : 7
  • Scores: 0
  • Reward points: 0
  • Joined: 2019/03/01 01:47:24
  • Status: offline
Re: DLP GUI option gone in 6.2.2 2019/11/04 08:30:29 (permalink)
0
You had to in ver 5, but now there is no feature to enable.
#3
Dave Hall
Expert Member
  • Total Posts : 1608
  • Scores: 174
  • Reward points: 0
  • Joined: 2012/05/11 07:55:58
  • Location: Canada
  • Status: offline
Re: DLP GUI option gone in 6.2.2 2019/11/04 11:07:25 (permalink)
0
The GUI options seem to have been removed completely in that version

Attached Image(s)


NSE4/FMG-VM64/FortiAnalyzer-VM/5.4/6.0 (FWF40C/FW92D/FGT200D/FGT101E)/ FAP220B/221C
#4
ianmclachlan
New Member
  • Total Posts : 7
  • Scores: 0
  • Reward points: 0
  • Joined: 2019/03/01 01:47:24
  • Status: offline
Re: DLP GUI option gone in 6.2.2 2019/11/05 06:24:05 (permalink)
0
:( Just as I'd feared.  I've discovered it's not working either.
#5
blntplt42
New Member
  • Total Posts : 1
  • Scores: 0
  • Reward points: 0
  • Joined: 2019/10/27 12:19:01
  • Status: offline
Re: DLP GUI option gone in 6.2.2 2019/11/17 06:09:17 (permalink)
0
Same problem. I asked distributor company in our country. They said "We have removed this feature in this release. It won't come any more. If you want dlp then you management dlp policy with gui"
Then I downgrade old firmware. This is unacceptable. I am thinking replace other brand firewall .
 
#6
nbctcp
Silver Member
  • Total Posts : 89
  • Scores: 4
  • Reward points: 0
  • Joined: 2015/03/05 04:48:26
  • Location: Indonesia
  • Status: offline
Re: DLP GUI option gone in 6.2.2 2020/01/10 01:49:54 (permalink)
0
Yes,
I notice.
I can create dlp filter and sensor in CLI but I can't put in policy
No "set dlp-sensor" anymore
 
FortiOS Cookbook 6.2.3 still mention DLP GUI on page 856, which is incorrect
The cookbook mention to use Web Filter instead of DLP
But on Web Filter
1. I can't add more extension such as .scr
2. I can't scan if target server using https or sftp
 
How to overcome those problems
 
tq
#7
mcdaniels
Bronze Member
  • Total Posts : 44
  • Scores: 0
  • Reward points: 0
  • Joined: 2013/05/15 05:29:31
  • Status: offline
Re: DLP GUI option gone in 6.2.2 2020/01/15 11:39:10 (permalink)
0
Hi folks,
I just realized, that all my DLP-Profiles are missing on my FG-60F @ OS 6.2.3 and -of course- just red the nice sentence "DLP Gui was removed".
 
so, now I had no of my old DLP profiles, which is a real problem. I used DLP the other way. I blocked certain filetypes from downloading.
 
Why Fortinet has removed this feature. I cannot see the point.
 
Very disappointing!!!
 
In my opinion this has a massive impact to security!
post edited by mcdaniels - 2020/01/15 11:40:20
#8
BGMIndustries
New Member
  • Total Posts : 3
  • Scores: -2
  • Reward points: 0
  • Joined: 2019/06/12 02:33:29
  • Status: offline
Re: DLP GUI option gone in 6.2.2 2020/02/10 02:55:13 (permalink)
1 (1)
Just came here to say I've just upgraded our new machines, which are going to replace a single FTG, to 6.2.3 and also realized there is no DLP Option from GUI anymore. I wouldn't mind re-creating all polices as Web Filter / E-Mail-Filter, but those filters lack the options to define my own patterns, I can only use the inbuilt onces. This is such a step backwards in security and I have no understanding why Fortinet is going backwards here. DLP was one of my most-used filters as it easily enabled me to control filetypes by patterns. Really disappointing.
#9
oxfordwhite84
New Member
  • Total Posts : 1
  • Scores: 0
  • Reward points: 0
  • Joined: 2020/02/11 12:15:11
  • Status: offline
Re: DLP GUI option gone in 6.2.2 2020/02/11 12:20:14 (permalink) ☄ Helpfulby nbctcp 2020/02/11 21:41:01
0
I just opened a case regarding this.
 You can apply it to a policy if you:
  1. create a policy
    1. You need to have the mode/type set to proxy
  2. In CLI edit the policy
  3. set utm-status enable
  4. NOW you can set the dlp-sensor
 
Hope that helps folks.
#10
nbctcp
Silver Member
  • Total Posts : 89
  • Scores: 4
  • Reward points: 0
  • Joined: 2015/03/05 04:48:26
  • Location: Indonesia
  • Status: offline
Re: DLP GUI option gone in 6.2.2 2020/02/11 21:42:54 (permalink)
0
at last DLP CLI working with some caveat in 6.2.3 vm eval license
1. It block zip even though zip not listed in filepattern
2. where to see dlp log in CLI

config dlp filepattern
edit 1
set name "DLP-BLOCKFILE"
config entries
edit "bat"
set filter-type type
set file-type bat
next
edit "com"
set filter-type type
next
edit "dll"
set filter-type type
next
edit "exe"
set filter-type type
next
edit "hta"
set filter-type type
next
edit "scr"
set filter-type type
next
edit "pif"
set filter-type type
next
edit "cpl"
set filter-type type
next
end
end
 
config dlp sensor
edit "default"
set comment "Default sensor."
config filter
edit 1
set proto smtp pop3 imap http-get http-post ftp nntp mapi
set filter-by file-type
set file-type 2
set action block
next
end
next
edit "sniffer-profile"
set comment "Log a summary of email and web traffic."
set summary-proto smtp pop3 imap http-get http-post
next
edit "DLP-BLOCKSENSOR"
config filter
edit 1
set proto smtp pop3 imap http-get http-post ftp mapi
set filter-by file-type
set file-type 1
set archive enable
set action block
next
end
set extended-log enable
next
end
 
config firewall policy
edit 1
set name "FGT1-SWtoWAN"
set srcintf "FGT1-SW"
set dstintf "port1"
set srcaddr "all"
set dstaddr "all"
set action accept
set schedule "always"
set service "ALL"
set utm-status enable
set inspection-mode proxy
set dlp-sensor "DLP-BLOCKSENSOR"
set logtraffic disable
set nat enable
next
#11
darwin_FTNT
Bronze Member
  • Total Posts : 43
  • Scores: 2
  • Reward points: 0
  • Joined: 2018/04/24 18:12:28
  • Status: offline
Re: DLP GUI option gone in 6.2.2 2020/02/13 16:20:37 (permalink)
0
I re-checked the code history for DLP removal.  Due to mantis 0546964 and 0473012.
It is to remove DLP from GUI but keep it in CLI due to existing users.
On the long run, the functionalities will be merged to other/existing utm profiles for code & performance improvement.
Basically, the functionality will not be removed but rather improved / with new features.

Cheers.
#12
Jump to:
© 2020 APG vNext Commercial Version 5.5