12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Log&Report<br />

Content Archive<br />

Content Archive<br />

The Content Archive menu enables you to view archived logs stored on the<br />

FortiAnalyzer unit from the <strong>FortiGate</strong> web-based manager. The Content Archive<br />

menu has four tabs, HTTP, FTP, Email, and IM where you can view each of these<br />

archived log types.<br />

Before viewing content archives, you need to enable this feature on your<br />

<strong>FortiGate</strong> unit. Content archiving is enabled from within a protection profile. See<br />

“Firewall Protection Profile” on page 329 for more information about enabling<br />

content archiving in a protection profile.<br />

You need to enable the following in the protection profile when configuring content<br />

summary/archive:<br />

• Antivirus for HTTP<br />

• HTTPS<br />

• Web URL Filter<br />

• HTTPS for Web Filter HTTPS<br />

The <strong>FortiGate</strong> unit only allows one sixteenth of its memory for transferring content<br />

archive files. For example, for <strong>FortiGate</strong> units with 128RAM, only 8MB of memory<br />

is used when transferring content archive files. It is re<strong>com</strong>mended not to enable<br />

full content archiving if antivirus scanning is also configured.<br />

Note: NNTP options will be supported in future releases.<br />

Configuring content archiving<br />

Content archiving is configured and enabled in the Firewall menu. Content<br />

archiving is only available when the <strong>FortiGate</strong> unit is configured to log to a<br />

FortiAnalyzer unit. The FortiGuard Analysis Service only provides content<br />

summary. If you are logging to the FortiGuard Analysis server, only None and<br />

Summary are available in the Archive to FortiAnalyzer/FortiGuard drop-down list.<br />

To enable content archiving for your <strong>FortiGate</strong> unit<br />

1 Go to Firewall > Protection Profile.<br />

2 Select the Edit icon beside a protection profile.<br />

3 Select the blue triangle to expand the Content Archive option.<br />

4 Select the check boxes you require for Display content meta-information on the<br />

system dashboard.<br />

5 Select None, Summary or Full from each drop-down list you require for Archive to<br />

FortiAnalyzer/FortiGuard.<br />

6 Select the checkbox for Archive SPAMed email to FortiAnalyzer, if required.<br />

7 Select OK.<br />

If you are logging to a FortiGuard Analysis server, you can only select None or<br />

Summary for the option, Archive to FortiAnalyzer/FortiGuard. FortiGuard Analysis<br />

Service only allows summary content archiving.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 491

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!