FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Not applicable
Article Id 194576
Description

This article describes steps required to block Windows streaming media content. This may be required by a system administrator as a measure to control time wasting and bandwidth misuse in a corporate environment.


Scope

Article can be applied to a VDOM or FortiGate unit running in transparent and/or NAT mode.


Solution
To block Windows media data streaming  

1. Go to Intrusion Protection > Signature and select Create New.

2.  Enter a name for the signature and enter the following text for the signature:

F-SBID( --name "Block.WMP.Get"; --default_action drop_session; --protocol tcp; --service HTTP; --flow from_client; --pattern "Pragma: xPlayStrm=1"; )

3.  Select OK.
 
sotoole_FD30044_FD30044-new_ips_custom.jpg
 

4.  Add custom signature to an IPS Sensor. To do this, go to Intrusion Protection > IPS Sensor and select Edit.
 
sotoole_FD30044_FD30044-add_custom_to_sensor.jpg
 

5.  Select Add Custom Override. Select the name of the custom signature and set the action to Reset or Block.
 
sotoole_FD30044_FD30044-add_custom_overide.JPG

 
sotoole_FD30044_FD30044-add_custom_overide_ii.jpg

sotoole_FD30044_FD30044-custom_sensor_ok.JPG
 

6.  Select OK.

7.  In this example the Custom Signature is added to the All_Default IPS Sensor group.
 
sotoole_FD30044_FD30044-view_all_default.jpg
 

8.  Go to Firewall > Protection Profile and edit the profile.  Select the expand arrow for IPS and view IPS Sensors in use.
sotoole_FD30044_FD30044-protection_profile_ips_to_use.jpg


9.  Make sure the sensor being used is that for which the custom signature has been added.

10.  Ensure this Protection Profile is in use by the Firewall policy.