FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Not applicable
Article Id 197412
Article
DescriptionFortiOS may allow a zero-byte file (a file with a size of 0 bytes) to pass through the FortiGate unit, that should be blocked or quarantined. Although this may be alarming to some customers, it is not a security risk.
ComponentsAll FortiGate units running all maintenance releases of FortiOS 2.80 or 3.0 up to FortiOS v3.0 MR3.
Steps or Commands

This problem may occur on a FortiGate unit with antivirus file blocking configured to quarantine blocked files to the FortiGate hard disk.

When you enable quarantine, the antivirus file blocking process ignores the file block when handling a zero-byte file, since the body of the file is zero bytes in size. As a result, a file that the antivirus file blocking should have blocked, passes through the FortiGate unit to its destination.

There is no chance of a security breach because a file of zero bytes cannot contain any harmful data.

If zero byte files that should be blocked are getting through your FortiGate unit and causing concern for your users, disabling quarantine for antivirus file blocking is a temporary fix that will stop the files from getting through.

Fortinet is working to fix this problem in a future FortiOS release.