4.2.7 Enable CDR for proxy mode on XLSB, OpenOffice, and RTF files

Information

Enabling Content Disarm & Reconstruction (CDR) for proxy mode on XLSB, OpenOffice, and RTF files enhances security by sanitizing potentially malicious content in these file types. This helps prevent threats embedded in documents while maintaining usability.

Note that, this is only applicable for AV profiles and firewall policies in \\"Proxy mode\\".

Enabling Content Disarm & Reconstruction (CDR) for XLSB, OpenOffice, and RTF files mitigates the risk of embedded malware by sanitizing potentially harmful content before it reaches the user. This proactive approach reduces the attack surface while ensuring business continuity.

Solution

To configure antivirus CDR in the GUI:

1. Go to Security Profiles > AntiVirus and click Create New.
2. Enable AntiVirus scan, and select Block.
3. Set Feature set to Proxy-based.
4. Under Inspected Protocols, enable one or more protocols that support proxy-based antivirus scanning.
5. Under APT Protection Options, enable Content Disarm and Reconstruction, and select Apply CDR to office files to disarm Microsoft Office and OpenOffice files, including RTF (Rich Text Format) and XLSB (Excel Binary Workbook) files.

Impact:

Without CDR, malicious payloads hidden in these document formats could bypass traditional security measures, leading to data breaches or system compromise.

See Also

https://workbench.cisecurity.org/benchmarks/24708

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: FortiGate

Control ID: b2efbd95694cdbed950ed6672f2705812be93a0953250d7d43e920074c864967