Blocking Upload of Webmail Attachments using Application Firewall for Hotmail.com/Outlook.com
03/26/2020 10 13017
DESCRIPTION: Blocking Upload of Webmail Attachments using Application Firewall for Hotmail.com/Outlook.com
This article describes the method to block uploading of email attachments in webmail. This method uses the HTTP URI Content option in Application Firewall Objects.HTTP URI Content field allows users to configure HTTP URI content and their respective values for Application Firewall to filter traffic. For more info on HTTP URI refer RFC 2616.
The method we use here is the HTTP URI Content "/mail/SilverlightAttachmentUploader.aspx". The following screen-capture shows the wireshark capture of a webmail attachment upload in outlook.com.
1. Although the solution described here has been tested, there is a possibility that it may affect traffic other than webmail.
2. Client DPI-SSL required, if using HTTPS.
Login to the SonicWall Management GUI.
Navigate to the Application Firewall > Application Objects page (Match Objects page in 220.127.116.11 and above).
Click on Add New Object and enter the following information:
Navigate to the FirewallApp Rules page.
Check the box under Enable App Rules.
Click on Add and create the following policy:
How to Test:
From a workstation behind the SonicWall, log into webmail. Try to upload an attachment. Check SonicWall logs and you will find logs similar to the one below.