12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Firewall Protection Profile<br />

Configuring a protection profile<br />

Oversized<br />

File/Email<br />

Add signature to<br />

outgoing emails<br />

Web filtering options<br />

Select block or pass for files and email messages exceeding<br />

configured thresholds for each protocol.<br />

Threshold<br />

See “AntiVirus” on page 397 for more antivirus configuration options.<br />

Figure 214:Protection profile web filtering options<br />

If the file is larger than the threshold value in<br />

megabytes, the file is passed or blocked, as set in the<br />

Oversized File/Email drop down. The maximum<br />

threshold for scanning in memory is 10% of the<br />

<strong>FortiGate</strong> unit RAM.<br />

Note: For email scanning, the oversize threshold<br />

refers to the final size of the email after encoding by<br />

the email client, including attachments. Email clients<br />

may use a variety of encoding types and some<br />

encoding types translate into larger file sizes than the<br />

original attachment. The most <strong>com</strong>mon encoding,<br />

base64, translates 3 bytes of binary data into 4 bytes<br />

of base64 data. So a file may be blocked or logged as<br />

oversized even if the attachment is several megabytes<br />

smaller than the configured oversize threshold.<br />

Create and enable a signature to append to outgoing email (SMTP<br />

only).<br />

The following options are available for web filtering through the protection profile.<br />

Web Content Block<br />

Web Content Exempt<br />

Web URL Filter<br />

ActiveX Filter<br />

Cookie Filter<br />

Java Applet Filter<br />

Enable or disable web page blocking for HTTP traffic based on<br />

the content block patterns in the content block list.<br />

Web content block drop-down list: Select which content<br />

block list will be used with this protection profile.<br />

Threshold: If the <strong>com</strong>bined scores of the content block<br />

patterns appearing on a web page exceed the threshold value,<br />

the page will be blocked. See “Viewing the web content block<br />

list” on page 427 for details.<br />

Enable or disable the override of web content block based on<br />

the content exempt patterns in the content exempt list.<br />

Web content exempt drop-down list: Select which content<br />

exempt list will be used with this protection profile.<br />

Enable or disable web page filtering for HTTP and HTTPS<br />

traffic based on the URL list.<br />

Web URL filter drop-down list: Select which web URL filter<br />

list will be used with this protection profile.<br />

Enable blocking of ActiveX controls.<br />

Enable blocking of cookies.<br />

Enable blocking of Java applets.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 333

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!