240
01-28011-0254-20051115
Fortinet Inc.
Protection profile
Firewall
Configuring web filtering options
Figure 114:Protection profile web filtering options
The following options are available for web filtering through the protection profile. See
“Web filter” on page 329
for more web filter configuration options.
Pass fragmented emails
Enable or disable passing fragmented email for mail protocols
(IMAP, POP3, SMTP). Fragmented email cannot be scanned for
viruses.
Oversized file/email
Select block or pass for files and email that exceed configured
thresholds for each protocol. To configure the oversized file
threshold, go to
Antivirus > Config > Config
. The maximum
threshold for scanning in memory is 10% of the FortiGate unit RAM.
Note:
For email scanning, the oversize threshold refers to the final
size of the email after encoding by the email client, including
attachments. Email clients may use a variety of encoding types and
some encoding types translate into larger file sizes than the original
attachment. The most common encoding, base64, translates 3
bytes of binary data into 4 bytes of base64 data. So a file may be
blocked or logged as oversized even if the attachment is several
megabytes less than the configured oversize threshold.
Add signature to
outgoing emails
Create and enable a signature to append to outgoing email (SMTP
only).
Web Content Block
Enable or disable web page blocking for HTTP traffic based on the
banned words and patterns in the content block list.
Web URL Block
Enable or disable web page filtering for HTTP traffic based on the
URL block list.
Web Exempt List
Enable or disable web page filtering for HTTP traffic based on the
URL exempt list. Exempt URLs are not scanned for viruses.
Web Script Filter
Enable or disable blocking scripts from web pages for HTTP traffic.
Web resume download
block
Enable to block downloading parts of a file that have already been
partially downloaded. Enabling this option will prevent the
unintentional download of virus files hidden in fragmented files.
Note that some types of files, such as PDF, fragment files to
increase download speed and enabling this option can cause
download interruptions.
Summary of Contents for FortiGate 1000A
Page 80: ...80 01 28011 0254 20051115 Fortinet Inc FortiGate IPv6 support System Network ...
Page 88: ...88 01 28011 0254 20051115 Fortinet Inc Dynamic IP System DHCP ...
Page 122: ...122 01 28011 0254 20051115 Fortinet Inc FortiManager System Config ...
Page 248: ...248 01 28011 0254 20051115 Fortinet Inc Protection profile Firewall ...
Page 260: ...260 01 28011 0254 20051115 Fortinet Inc CLI configuration User ...
Page 380: ...380 01 28011 0254 20051115 Fortinet Inc CLI configuration Log Report ...
Page 392: ...392 01 28011 0254 20051115 Fortinet Inc Glossary ...