Skip to main content
ederwindows98
New Member
July 6, 2021
Question

Fortigate 60E - Configuring Antivirus - EICAR file test don't blocked

  • July 6, 2021
  • 5 replies
  • 14407 views

Hi!

I'm configuring the antivirus for first time in the Fortios 5.4.6. I follow this cookbook:

https://docs.fortinet.com/document/fortigate/5.4.0/cookbook/350705/inspecting-traffic-content-using-flow-based-inspection

But when i test the configuration with the EICAR file test it don't block the download.

Here my screenshots of police:

Thank you everybody!

    5 replies

    druber
    New Member
    July 6, 2021

    ederwindows98 wrote:

    Hi!

    I'm configuring the antivirus for first time in the Fortios 5.4.6. I follow this cookbook:

    https://docs.fortinet.com/document/fortigate/5.4.0/cookbook/350705/inspecting-traffic-content-using-flow-based-inspection

    But when i test the configuration with the EICAR file test it don't block the download.

    Here my screenshots of police:

    Thank you everybody!

    Same here.  I just purchased license for AV, and the GUI confirms I am licensed.  Yet, applying the AV profile as above, when I go to the eicar site, I am allowed to download anything there.  And the stats show:

     

    gateway # diagnose ips av stats show AV stats: HTTP virus detected: 0 HTTP virus blocked: 0 SMTP virus detected: 0 SMTP virus blocked: 0 POP3 virus detected: 0 POP3 virus blocked: 0 IMAP virus detected: 0 IMAP virus blocked: 0 NNTP virus detected: 0 NNTP virus blocked: 0 FTP virus detected: 0 FTP virus blocked: 0 SMB virus detected: 0 SMB virus blocked: 0

    Looking at that command makes me wonder: do I need IPS turned on for this?  The docs are extremely detailed about some things, but don't mention some pretty basic nuts and bolts.

    Jirka1
    Explorer II
    July 6, 2021

    Hi,

     

    did you use this page? https://www.eicar.org/?page_id=3950 If so the download is via https only. In order to block the AV threat, you must have SSL deep inspection enabled. Jirka

    druber
    New Member
    July 6, 2021

    yeah, crossing emails :)  thanks for confirming this...

    ederwindows98
    New Member
    July 12, 2021

    Thanks guy!

    I'm newbie in the fortigate configurations.

    In the ssl inspection profiles there are a deep-inspection profile.

    But it doesn't show when I open the list in the Edit policy page.

    I should enable it per cli?

     

     

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!