12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Quarantine<br />

AntiVirus<br />

Using the allow action, this behavior can be reversed with all files being blocked<br />

unless explicitly passed. Simply enter all the file patterns to be passed with the<br />

allow attribute. At the end of the list, add an all-inclusive wildcard (*.*) with a block<br />

action. Allowed files continue to antivirus scanning (if enabled) while files not<br />

matching any allowed patterns are blocked by the wildcard at the end.<br />

The file pattern list is preconfigured with a default list of file patterns:<br />

• executable files (*.bat, *.<strong>com</strong>, and *.exe)<br />

• <strong>com</strong>pressed or archive files (*.gz, *.rar, *.tar, *.tgz, and *.zip)<br />

• dynamic link libraries (*.dll)<br />

• HTML application (*.hta)<br />

• Microsoft Office files (*.doc, *.ppt, *.xl?)<br />

• Microsoft Works files (*.wps)<br />

• Visual Basic files (*.vb?)<br />

• screen saver files (*.scr)<br />

• program information files (*.pif)<br />

File pattern is enabled in protection profiles. For more information, see “Antivirus<br />

options” on page 332.<br />

Configuring the file pattern list<br />

File patterns can be up to 80 characters long. The maximum number of file<br />

patterns in a list is 5000.<br />

To add a new file pattern while viewing a file pattern list, select Create New. To edit<br />

an existing file pattern, select the edit icon associated with the pattern.<br />

Figure 271:New file pattern<br />

Pattern<br />

Action<br />

Enable<br />

Enter the file pattern.The file pattern can be an exact file name or<br />

can include wildcards.<br />

Select an action from the drop down list: Block or Allow.<br />

Select to enable the pattern.<br />

Quarantine<br />

<strong>FortiGate</strong> units with a local disk can quarantine blocked and infected files. View<br />

the file name and status information about the file in the quarantined file list.<br />

Submit specific files and add file patterns to the AutoSubmit list so they will<br />

automatically be uploaded to Fortinet for analysis.<br />

<strong>FortiGate</strong> units without a local disk can quarantine blocked and infected files to a<br />

FortiAnalyzer unit. Files stored on the FortiAnalyzer can be retrieved for viewing.<br />

To configure the FortiAnalyzer unit, go to Log & Report > Log Config > Log<br />

Setting.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

402 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!