File Blocking; Blocking Files In Firewall Traffic; Adding File Patterns To Block - Fortinet FortiGate 50A Installation And Configuration Manual

Fortinet fortigate installation and configuration guide
Hide thumbs Also See for FortiGate 50A:
Table of Contents

Advertisement

Antivirus protection

File blocking

Blocking files in firewall traffic

Adding file patterns to block

FortiGate-50A Installation and Configuration Guide
Enable file blocking to remove all files that are a potential threat and to provide the
best protection from active computer virus attacks. Blocking files is the only protection
from a virus that is so new that antivirus scanning cannot detect it. You would not
normally operate the FortiGate unit with blocking enabled. However, it is available for
extremely high-risk situations in which there is no other way to prevent viruses from
entering your network.
File blocking deletes all files that match a list of enabled file patterns. The FortiGate
unit replaces the file with an alert message that is forwarded to the user. The
FortiGate unit also writes a message to the virus log and sends an alert email if it is
configured to do so.
Note: If both blocking and scanning are enabled, the FortiGate unit blocks files that match
enabled file patterns and does not scan these files for viruses.
By default, when blocking is enabled, the FortiGate unit blocks the following file
patterns:
executable files (*.bat, *.com, and *.exe)
compressed or archive files (*.gz, *.rar, *.tar, *.tgz, and *.zip)
dynamic link libraries (*.dll)
HTML application (*.hta)
Microsoft Office files (*.doc, *.ppt, *.xl?)
Microsoft Works files (*.wps)
Visual Basic files (*.vb?)
screen saver files (*.scr)
Use content profiles to apply file blocking to HTTP, FTP, POP3, IMAP, and SMTP
traffic controlled by firewall policies.
To block files in firewall traffic
1
Select file blocking in a content profile.
See
"Adding content profiles" on page
2
Add this content profile to firewall policies to apply content blocking to the traffic
controlled by the firewall policy.
See
"Adding content profiles to policies" on page
To add file patterns to block
1
Go to Anti-Virus > File Block.
2
Select New.
167.
169.
File blocking
227

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents

Save PDF