To test your file blocking configuration, access an endpoint
PC in the trust zone and attempt to download an executable file
from a website in the untrust zone; a response page should display.
Click
Continue to confirm that you can download
the file. You can also set other actions, such as
alert or
block,
which don't provide an option for the user to continue the download.
The following shows the default response page for File Blocking:
(
Optional) Define custom file blocking response pages (). This allows you to provide more information to users when they
see a response page. You can include information such as company policy
information and contact information for a Helpdesk.
When you create a file blocking profile with the
continue action, you can choose only the
web-browsing application. If you choose any
other application, traffic that matches the security policy won't flow
through because users are not prompted with an option to continue.
Additionally, you need to configure and enable a decryption policy for
HTTPS websites.
Check your logs to determine the application used when you test this
feature. For example, if you're using Microsoft SharePoint to download
files, even though you're using a web-browser to access the site, the
application is actually sharepoint-base, or
sharepoint-document. (It can help to
set the application type to Any for testing.)