Firewall
Protection profile
FortiGate-5000 series Administration Guide
01-28008-0013-20050204
235
Configuring web filtering options
Figure 113:Protection profile web filtering options
The following options are available for web filtering through the protection profile. See
“Web filter” on page 319
for more web filter configuration options.
Pass fragmented emails
Enable or disable passing fragmented email for mail protocols
(IMAP, POP3, SMTP). Fragmented email cannot be scanned for
viruses.
Oversized file/email
Select block or pass for files and email that exceed configured
thresholds for each protocol. To configure the oversized file
threshold, go to
Antivirus > Config > Config
. The maximum
threshold for scanning in memory is 10% of the FortiGate unit RAM.
Note:
For email scanning, the oversize threshold refers to the final
size of the email after encoding by the email client, including
attachments. Email clients may use a variety of encoding types and
some encoding types translate into larger file sizes than the original
attachment. The most common encoding, base64, translates 3
bytes of binary data into 4 bytes of base64 data. So a file may be
blocked or logged as oversized even if the attachment is several
megabytes less than the configured oversize threshold.
Add signature to
outgoing emails
Create and enable a signature to append to outgoing email (SMTP
only).
Web Content Block
Enable or disable web page blocking for HTTP traffic based on the
banned words and patterns in the content block list.
Web URL Block
Enable or disable web page filtering for HTTP traffic based on the
URL block list.
Web Exempt List
Enable or disable web page filtering for HTTP traffic based on the
URL exempt list. Exempt URLs are not scanned for viruses.
Web Script Filter
Enable or disable blocking scripts from web pages for HTTP traffic.
Web resume download
block
Enable to block downloading parts of a file that have already been
partially downloaded. Enabling this option will prevent the
unintentional download of virus files hidden in fragmented files.
Note that some types of files, such as PDF, fragment files to
increase download speed and enabling this option can cause
download interruptions.
Summary of Contents for FortiGate FortiGate-5020
Page 86: ...86 01 28008 0013 20050204 Fortinet Inc Dynamic IP System DHCP ...
Page 118: ...118 01 28008 0013 20050204 Fortinet Inc FortiManager System Config ...
Page 254: ...254 01 28008 0013 20050204 Fortinet Inc CLI configuration User ...
Page 318: ...318 01 28008 0013 20050204 Fortinet Inc CLI configuration Antivirus ...
Page 350: ...350 01 28008 0013 20050204 Fortinet Inc Using Perl regular expressions Spam filter ...
Page 370: ...370 01 28008 0013 20050204 Fortinet Inc CLI configuration Log Report ...
Page 382: ...382 01 28008 0013 20050204 Fortinet Inc Glossary ...
Page 402: ...402 01 28008 0013 20050204 Fortinet Inc Index ...