324
01-28006-0010-20041105
Fortinet Inc.
CLI configuration
Antivirus
service http
Use this command to configure how the FortiGate unit handles antivirus scanning of
large files and what ports the FortiGate unit virus scans for HTTP traffic.
Command syntax pattern
config antivirus service http
set <keyword> <variable>
end
config antivirus service http
unset <keyword>
end
get antivirus service [http]
show antivirus service [http]
Example
This example shows how to add antivirus scanning for HTTP traffic on ports 70, 90,
and 443. Adding more ports for scanning does not erase the default, port 80. Use the
unset
command to remove all ports from the list.
config antivirus service http
set port 70
set port 90
set port 443
end
antivirus quarantine command keywords and variables
Keywords and variables
Description
Default
Availability
drop_heuristic
{ftp http imap pop3 smtp}
Do not quarantine files found by
heuristic scanning in traffic for the
specified protocols.
imap
smtp
pop3
http
ftp
FortiGate
models
numbered
200 and
higher.
store_heuristic
{ftp http imap pop3 smtp}
Quarantine files found by heuristic
scanning in traffic for the specified
protocols.
No
default.
FortiGate
models
numbered
200 and
higher.
Note:
This command has more keywords than are listed in this Guide. See the
FortiGate CLI
Reference Guide
for a complete list of commands and keywords.
Table 27: antivirus service http command keywords and variables
Keywords and variables
Description
Default Availability
port <port_integer>
Configure antivirus scanning on a
nonstandard port number or
multiple port numbers for HTTP.
You can use ports from the range
1-65535. You can add up to 20
ports.
80
All models.
Summary of Contents for FortiGate 3000
Page 18: ...Contents 18 01 28006 0010 20041105 Fortinet Inc ...
Page 52: ...52 01 28006 0010 20041105 Fortinet Inc Changing the FortiGate firmware System status ...
Page 78: ...78 01 28006 0010 20041105 Fortinet Inc FortiGate IPv6 support System network ...
Page 86: ...86 01 28006 0010 20041105 Fortinet Inc Dynamic IP System DHCP ...
Page 116: ...116 01 28006 0010 20041105 Fortinet Inc FortiManager System config ...
Page 122: ...122 01 28006 0010 20041105 Fortinet Inc Access profiles System administration ...
Page 252: ...252 01 28006 0010 20041105 Fortinet Inc CLI configuration Users and authentication ...
Page 390: ...390 01 28006 0010 20041105 Fortinet Inc Glossary ...
Page 398: ...398 01 28006 0010 20041105 Fortinet Inc Index ...