12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

AntiVirus<br />

Order of operations<br />

AntiVirus<br />

This section describes how to configure the antivirus options associated with<br />

firewall protection profiles.<br />

This section describes:<br />

• Order of operations<br />

• Antivirus elements<br />

• Antivirus settings and controls<br />

• File pattern<br />

• Quarantine<br />

• Config<br />

• Antivirus CLI configuration<br />

Order of operations<br />

Antivirus processing includes various modules and engines that perform separate<br />

tasks. The <strong>FortiGate</strong> unit performs antivirus processing in the order the elements<br />

appear in the web-based manager menu:<br />

• File pattern<br />

• Virus scan<br />

• Grayware<br />

• Heuristics<br />

If a file fails any of the elements of the antivirus scan, no further scans are<br />

performed. For example, if the file “fakefile.EXE”, is recognized as a blocked<br />

pattern, the <strong>FortiGate</strong> unit will send the end user a replacement message and the<br />

file will be deleted or quarantined. The virus scan, grayware and heuristic scans<br />

will not be performed as the file is already found to be a threat and has been dealt<br />

with; there is no need to use further system resources on the file at this time.<br />

Antivirus elements<br />

The antivirus elements work in sequence to give you an efficient method of<br />

scanning in<strong>com</strong>ing files. The first three elements have specific functions, the<br />

fourth, the heuristics, is to cover any new, previously unknown, virus threats. The<br />

four elements work together to offer your network unparalleled antivirus<br />

protection. To ensure that your system is providing the most protection available,<br />

all virus definitions and signatures are up dated regularly through the FortiGuard<br />

antivirus services. The elements will be discussed in the order that they are<br />

applied followed by FortiGuard antivirus.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 397

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!