: Set Up File Blocking on Cloud NGFW for AWS
Focus
Focus

Set Up File Blocking on Cloud NGFW for AWS

Table of Contents

Set Up File Blocking on Cloud NGFW for AWS

File Blocking allows you to identify specific file types that you want to block or monitor. For most traffic (including traffic on your internal network), block files that are known to carry threats or that have no real use case for upload/download. These include batch files, DLLs, Java class files, help files, Windows shortcuts (.lnk), and BitTorrent files.
Cloud NGFW can take the following actions on files moving through your network.
  • Alert
    —When the specified file type is detected, a log is generated in the data filtering log.
  • Block
    —When the specified file type is detected, the file is blocked and a customizable block page is presented to the user. A log is also generated in the data filtering log.
  • Continue
    —When the specified file type is detected, a response page is presented to the user. The user can click through the page to download the file. A log is also generated in the data filtering log. Because this type of forwarding action requires user interaction, it is only applicable for web traffic.
In addition, you can allow or block file types based on the direction they are going—Download, Upload, or Upload and Download.
  1. Select
    Rulestacks
    and select a previously-created rulestack on which to configure file blocking.
  2. Select
    Security Profiles
    Malware and File-based Threat Protection
    File Blocking
    Edit
    .
  3. Select the file type or types from the displayed list.
  4. Set the
    Action
    and
    Direction of traffic
    for the selected file types from the drop-downs.
  5. Click
    Save
    .

Change the File Blocking Profile

By default, the file blocking profile is set to
best practice
. To change the file blocking profile:
  1. In the
    Malware and File-based Threat Protection
    screen, navigate to
    File Blocking
    .
  2. Use the drop-down to select
    Custom
    .
  3. Open the Cloud NGFW console. Navigate to
    Rulestacks > Rulestack name > Security Services > File Blocking
    .
  4. In the
    Set Action
    drop-down, change the action to
    Alert
    or
    Continue
    .

Recommended For You