File Blocking Shootout – Palo Alto vs. Fortinet 2018-06-27 Fortinet , Palo Alto Networks , Password Data Leak Prevention , DLP , Encrypted , fail , File Blocking , FortiGate , Fortinet , Microsoft Office , Palo Alto Networks , Password , PDF , Protected , ZIP Johannes Weber We needed to configure the Internet-facing firewall for a customer to block encrypted files such as protected PDF, ZIP, or Microsoft Office documents. We tested it with two next-generation firewalls, namely Fortinet FortiGate and Palo Alto Networks. The experiences were quite different… TL;DR: While Fortinet is able to block encrypted files, Palo Alto fails since it does not identify encrypted office documents! [ UPDATE : Palo Alto has fixed the main problem, see notes below.] Note that the Internet connection must be either unencrypted itself, i.e., HTTP or FTP, or some TLS inspection/MITM technique...