226
01-28007-0144-20041217
Fortinet Inc.
Protection profile
Firewall
Configuring antivirus options
Figure 107:Protection profile antivirus options
The following options are available for antivirus through the protection profile. See
“Antivirus” on page 291
for more antivirus configuration options.
Virus Scan
Enable or disable virus scanning (for viruses and worms) for each
protocol (HTTP, FTP, IMAP, POP3, SMTP). Grayware, if enabled in
Antivirus > Config > Config, is included with the Virus Scan.
Heuristic, if enabled in the CLI, is also included with the Virus Scan.
File Block
Enable or disable file pattern blocking for each protocol. You can
block files by name, by extension, or any other pattern, giving you
the flexibility to block files that may contain harmful content.
Quarantine (models with
local disk only)
Enable or disable quarantining for each protocol. You can
quarantine suspect files to view them or submit files to Fortinet for
analysis.
Pass fragmented emails
Enable or disable passing fragmented email for mail protocols
(IMAP, POP3, SMTP). Fragmented email cannot be scanned for
viruses.
Oversized file/email
Select block or pass for files and email that exceed configured
thresholds for each protocol. To configure the oversized file
threshold, go to
Antivirus > Config > Config
. The maximum
threshold for scanning in memory is 10% of the FortiGate unit RAM.
Note:
For email scanning, the oversize threshold refers to the final
size of the email after encoding by the email client, including
attachments. Email clients may use a variety of encoding types and
some encoding types translate into larger file sizes than the original
attachment. The most common encoding, base64, translates 3
bytes of binary data into 4 bytes of base64 data. So a file may be
blocked or logged as oversized even if the attachment is several
megabytes less than the configured oversize threshold.
Add signature to
outgoing emails
Create and enable a signature to append to outgoing email (SMTP
only).
Summary of Contents for FortiGate FortiGate-60M
Page 12: ...Contents 12 01 28007 0144 20041217 Fortinet Inc Index 369 ...
Page 44: ...44 01 28007 0144 20041217 Fortinet Inc Changing the FortiGate firmware System status ...
Page 74: ...74 01 28007 0144 20041217 Fortinet Inc FortiGate IPv6 support System network ...
Page 82: ...82 01 28007 0144 20041217 Fortinet Inc Dynamic IP System DHCP ...
Page 116: ...116 01 28007 0144 20041217 Fortinet Inc Access profiles System administration ...
Page 234: ...234 01 28007 0144 20041217 Fortinet Inc Protection profile Firewall ...
Page 246: ...246 01 28007 0144 20041217 Fortinet Inc CLI configuration Users and authentication ...
Page 278: ...278 01 28007 0144 20041217 Fortinet Inc CLI configuration VPN ...
Page 340: ...340 01 28007 0144 20041217 Fortinet Inc Using Perl regular expressions Spam filter ...
Page 358: ...358 01 28007 0144 20041217 Fortinet Inc CLI configuration Log Report ...
Page 376: ...376 01 28007 0144 20041217 Fortinet Inc Index ...