Skip to main content
leonardo_ortiz
New Member
August 8, 2018
Question

HTTP EVADER

  • August 8, 2018
  • 1 reply
  • 7285 views

Hello.

 

Fortigate can't pass in http evader tests from noxxi.de, using SSL Deep Inspection, AV, IPS etc. Running last FortiOS 5.6.

Have some recommendation or best pratice for attacks like this?

Test: https://noxxi.de/research/http-evader-testsite.html

 

    1 reply

    Hosemacht
    Explorer
    August 8, 2018

    Hey there,

     

    yes fortios 5.6 can pass this test.

     

    update to the latest 5.6 (5.6.5) and then

    you have to enable av heuristics and most important use the extendet ips database and then set Action to block

    in the security profiles.

    if you use "default" instead of "block" in the ips profile, the eicar Virus will not be blocked.

     

    run the test again

    OberonX
    New Member
    January 9, 2020

    Hi, I followed the steps mentioned but I still don't pass the evader test, I´m running FortiOS 6.0.8 version

    Hosemacht
    Explorer
    January 10, 2020

    Hey there,

     

    please have a look at you ips logs, are there any eicar virus test file messages and are they blocked?

     

    Regards