Skip to main content
bkarl
Staff
Staff
September 11, 2023

Technical Tip: How to set correctly Antivirus for EICAR test

  • September 11, 2023
  • 0 replies
  • 7697 views
Description

This article describes the correct way to combine File Filter and Antivirus profile to avoid EICAR malicious file access.

Scope FortiGate v7.4.0.
Solution
  1. Make sure to have a firewall policy set on proxy inspection mode, the Antivirus profile and File Filter are set on proxy mode.
  2. Make sure to have the firewall operating in profile mode.
  3. In this example, default profile and Deep inspection are enabled.
  4. Do not forget to install certificate CA on the PC to protect it.
  5. It is possible to test with Eicar's anti-malware test file.
  6. Download any of the following files and a blocking message like this one will appear:

 

KB 22 - 1.jpg

 

KB 22 - 2.jpg


date=2025-09-25 time=02:57:49 eventtime=1758794268860360434 tz="-0700" logid="0211008192" type="utm" subtype="virus" eventtype="infected" level="warning" vd="root" policyid=8 poluuid="acfe8828-564c-51f0-9e45-c451ae68d1de" policytype="policy" msg="File is infected." action="blocked" service="HTTPS" sessionid=354536291 srcip=10.187.17.245 dstip=89.238.73.97 srcport=55914 dstport=443 srccountry="Reserved" dstcountry="Germany" srcintf="port4" srcintfrole="undefined" dstintf="port1" dstintfrole="undefined" srcuuid="d42df33a-2f13-51f0-b7cf-b3cd98be54d3" dstuuid="d42df33a-2f13-51f0-b7cf-b3cd98be54d3" proto=6 direction="incoming" filename="eicarcom2.zip" quarskip="Quarantine-disabled" virus="EICAR_TEST_FILE" viruscat="Virus" dtype="av-engine" ref="https://fortiguard.com/encyclopedia/virus/2172" virusid=2172 url="https://secure.eicar.org/eicarcom2.zip" profile="default" agent="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36" httpmethod="GET" referralurl="https://www.eicar.org/" analyticscksum="e1105070ba828007508566e28a2b8d4c65d192e9eaf3b7868382b7cae747b397" analyticssubmit="false" crscore=50 craction=2 crlevel="critical"

 

To install certificate Fortinet_CA_SSL:

'Double-click' on the .cert file, select the Install option -> Local PC/Device, place all certificates on the following store, choose the second folder, select next, and then, select 'Finish'.

 

KB 22 - 4.jpg

 

KB 22 - 3.jpg

 

Related documents: