20
01-28011-0254-20051115
Fortinet Inc.
About the FortiOS International and US Domestic distributions
Introduction
Logging and reporting
The FortiGate unit supports logging for various categories of traffic and configuration
changes. You can configure logging to:
• report traffic that connects to the firewall,
• report network services used,
• report traffic that was permitted by firewall policies,
• report traffic that was denied by firewall policies,
• report events such as configuration changes and other management events,
IPSec tunnel negotiation, virus detection, attacks, and web page blocking,
• report attacks detected by the IPS,
• send alert email to system administrators to report virus incidents, intrusions, and
firewall or VPN events or violations.
Logs can be sent to a remote syslog server or a WebTrends NetIQ Security Reporting
Center and Firewall Suite server using the WebTrends enhanced log format. Some
models can also save logs to an optional internal hard drive. If a hard drive is not
installed, you can configure most FortiGate units to log the most recent events and
attacks detected by the IPS to the system memory.
About the FortiOS International and US Domestic distributions
Fortinet produces two distributions of FortiOS v3.0, an International distribution and a
US Domestic distribution. The International distribution is available to users outside of
the United States and the US Domestic distribution is available to all users, including
users in the United States.
The main difference between the US Domestic and International distributions of
FortiOS is the Antivirus engine. The US Domestic Antivirus engine processes SMTP
traffic in streaming mode with object based scanning. The US Domestic Antivirus
engine also uses a new hot list antivirus scanning technique for all protocols (HTTP,
FTP, IMAP, POP3, SMTP, and IM). Streaming mode is also called splice mode.
US Domestic distribution changes
If you are operating your FortiGate unit with the US Domestic distribution, on the
web-based manager System Status page unit Unit Information, Distribution is set to
US Domestic (see
“System Status” on page 33
). In addition the US Domestic
distribution firmware has the following changes:
•
SMTP virus scanning only operates in streaming mode
•
Spam filter email tagging for SMTP is not supported
•
SMTP quarantine file name system generated
•
The default mail virus replacement message (splice mode) is changed
Summary of Contents for FortiGate 1000A
Page 80: ...80 01 28011 0254 20051115 Fortinet Inc FortiGate IPv6 support System Network ...
Page 88: ...88 01 28011 0254 20051115 Fortinet Inc Dynamic IP System DHCP ...
Page 122: ...122 01 28011 0254 20051115 Fortinet Inc FortiManager System Config ...
Page 248: ...248 01 28011 0254 20051115 Fortinet Inc Protection profile Firewall ...
Page 260: ...260 01 28011 0254 20051115 Fortinet Inc CLI configuration User ...
Page 380: ...380 01 28011 0254 20051115 Fortinet Inc CLI configuration Log Report ...
Page 392: ...392 01 28011 0254 20051115 Fortinet Inc Glossary ...