Skip to main content
zoriax
New Member
April 21, 2022
Question

FortiGate Antivirus is blocking but not logging

  • April 21, 2022
  • 12 replies
  • 11250 views

Hi everyone,

 

Very strange behaviour with FortiGate and AntiVirus in firewall rule. I have sometime my traffic blocked by AntiVirus but I can't see anything in logs.

 

In my Forward Traffic logs, I can see sometimes a value in result, sometimes not. When Result is green and has traffic, AntiVirus is disabled and request correctly pass. When Result is empty, traffic is blocked and AntiVirus is enabled on policy.

zoriax_0-1650533079162.png

 

If I looked inside AntiVirus logs, the are empty. My AntiVirus configuration is here : 

 

zoriax_1-1650533271572.png

 

I tried to disabled one by one each part of AntiVirus configuration but no change. The request is working only if I disabled AntiVirus in firewall rule.

 

I've mistaken somewhere or is it a bug ? If a virus is detected, why I don't have any log ? For me it looks like an AntiVirus engine bug...

 

Maybe you have more tools to debug this behaviour :)

 

Thanks for your help

12 replies

AlexC-FTNT
Staff
Staff
April 21, 2022

If you don't see any logs, why do you think it is blocked by the AV?

And where do you look for AV logs? You can find the AV logs in the dedicated Antivirus section of Log & Report (not in Forward traffic) if logging is enabled in policy. 

zoriax
zoriaxAuthor
New Member
April 21, 2022

Hi ! 

 

I suspected the AV beacause if I disabled it form my policy, here : 

zoriax_0-1650534195811.png

My request is correctyl forwarded. If I changed it to : 

zoriax_1-1650534222577.png

My request is not working correctly.

 

My AntiVirus logs are totally empty... 

AlexC-FTNT
Staff
Staff
April 21, 2022

Once again, this is not a proof of a log problem. The traffic may be blocked by a wrongly configured AV (or maybe a bug). Make sure that AV profile mode is consistent with the policy operation mode (proxy-mode). Also, check that the FortiOS version you are running is up to date (6.4.8 / 7.0.5) to eliminate possible bugs.

zoriax
zoriaxAuthor
New Member
April 21, 2022

For me the problem seems to be related to AV more than log... Or something strange in AV that is not logged (a bug maybe...)

 

If I follow you, I need to pass my policy to Proxy-baded inspection if I wanted to user AV in profile ? I'm a bit confuse about that... 

 

Thanks for your return.

AlexC-FTNT
Staff
Staff
April 21, 2022

Yes. In flow-based mode only IPS and Webfilter work correctly.

For other inspection profiles, the policy must to be in proxy-based mode to offer proper results. 

Jirka1
Explorer II
April 21, 2022

Hi Alex,

what exactly do you mean by: "Yes. In flow-based mode only IPS and Webfilter work correctly. For other inspection profiles, the policy must be in proxy-based mode to offer proper results."

 

Does this mean that, for example, application control or antivirus does not work in Flow mode? Or is their functionality reduced? How do I understand that?

Thank you.

Jirka1_0-1650561560697.png

 



Jirka

AlexC-FTNT
Staff
Staff
April 22, 2022

You may get some false positive identifications in flow-based mode, or impossible to block the stream/connection after a positive identification.

AV/AppControl works on 'best effort' basis since the packets are not buffered (proxied).

Surely, flow-based inspection is 'lighter' on resource usage.

zoriax
zoriaxAuthor
New Member
April 21, 2022

As I can see in version 7.0.5, AntiVirus seems to work correctly with the 2 types : 

 

zoriax_0-1650544145578.png

 

But I tried proxy-mode in my firewall rule and it works now correctly...

 

So your recommandation is to always set proxy-based when AV is needed ?

 

zoriax
zoriaxAuthor
New Member
April 21, 2022

Just to clarify the configuraiton of Policy and AV I can set : 

  • Flow-based / Proxy-based in Policies
  • Flow-based / Proxy-based in AntiVirus

If I understand correctly I must set Proxy-Based in policies and I can choose inspection in AV right ?

AlexC-FTNT
Staff
Staff
April 21, 2022

if your policy is proxy-based, your AV profile MUST be proxy-based

if your policy is flow-based, your AV profile MUST be flow-based

zoriax
zoriaxAuthor
New Member
April 21, 2022

OK I understand. But in fact I can set a proxy-based firewall policy with a flow-based AV policy... No warning and AV works correctly.

 

So you recommand to add proxy-based with AV or flow-based ? Both of them works but not in the same way. And as I can see in my case proxy-based with AV works but not flow-based... 

zoriax
zoriaxAuthor
New Member
April 21, 2022

Someone can share with me his best practice / recommandation ? 

Thanks :)

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.