EasyManuals Logo

Fortinet FortiGate 100 Installation & Configuration Guide

Fortinet FortiGate 100
272 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #233 background imageLoading...
Page #233 background image
Antivirus protection Blocking files in firewall traffic
FortiGate-100 Installation and Configuration Guide 233
File blocking
Enable file blocking to remove all files that pose a potential threat and to provide the
best protection from active computer virus attacks. Blocking files is the only protection
available from a virus that is so new that antivirus scanning cannot detect it. You
would not normally run the FortiGate unit with blocking enabled. However, it is
available for extremely high-risk situations in which there is no other way to prevent
viruses from entering your network.
File blocking deletes all files that match a list of enabled file patterns. The FortiGate
unit replaces the file with an alert message that is forwarded to the user. The
FortiGate unit also writes a message to the virus log and sends an alert email if it is
configured to do so.
By default, when blocking is enabled, the FortiGate unit blocks the following file
patterns:
executable files (*.bat, *.com, and *.exe)
compressed or archive files (*.gz, *.rar, *.tar, *.tgz, and *.zip)
dynamic link libraries (*.dll)
HTML application (*.hta)
Microsoft Office files (*.doc, *.ppt, *.xl?)
Microsoft Works files (*.wps)
Visual Basic files (*.vb?)
screen saver files (*.scr)
Blocking files in firewall traffic
Use content profiles to apply file blocking to HTTP, FTP, POP3, IMAP, and SMTP
traffic controlled by firewall policies.
1 Select file blocking in a content profile.
See “Adding a content profile” on page 170.
2 Add this content profile to firewall policies to apply content blocking to the traffic
controlled by the firewall policy.
See “Adding a content profile to a policy” on page 171.
Adding file patterns to block
1 Go to Anti-Virus > File Block.
2 Select New.
3 Type the new pattern in the File Pattern field.
You can use an asterisk (*) to represent any characters and a question mark (?) to
represent any single character. For example, *.dot blocks Microsoft Word template
files and *.do? blocks both Microsoft Word template files and document files.
4 Select the check box beside the traffic protocols for which you want to enable blocking
of this file pattern.
5 Select OK.
Note: If both blocking and scanning are enabled, the FortiGate unit blocks files that
match enabled file patterns and does not scan these files for viruses.

Table of Contents

Other manuals for Fortinet FortiGate 100

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Fortinet FortiGate 100 and is the answer not in the manual?

Fortinet FortiGate 100 Specifications

General IconGeneral
BrandFortinet
ModelFortiGate 100
CategoryGateway
LanguageEnglish

Related product manuals