Skip to main content
Malik
New Member
August 23, 2017
Solved

Is it normal to receive too much threat/viruses?

  • August 23, 2017
  • 4 replies
  • 5834 views

Hi,

 

In my fortimail log (installed in fortimanager) I can find so many threat/viruses, like 1 email with infected file each 2 or 10 Seconds.

 

With dynamic sources (Majority asia). What I want to know, if you are experiencing the same events in your fortimail? And what are some best practice to reinforce my fortimail and security in general? (I have only fortinet product for security)

 

Thank you for your answers.

 

 

    Best answer by neonbit

    I sometimes see floods like that when there's a virus outbreak.

     

    My biggest recommendation to reinforce your FortiMail is to get FortiSandbox (either cloud service or local appliance). While the FortiMails virus scanner is great, the FortiSandbox will be able help detect and block 0 day viruses where no signature exists. 

     

    I'd also recommend looking at blocking password encrypted files. If your FortiMail cant decrypt it then it can't scan it. FYI there's a new feature with the latest version of FortiMail where it can use words in an email to try and decrypt files but I haven't tested it yet.

    4 replies

    neonbit
    neonbitAnswer
    New Member
    August 23, 2017

    I sometimes see floods like that when there's a virus outbreak.

     

    My biggest recommendation to reinforce your FortiMail is to get FortiSandbox (either cloud service or local appliance). While the FortiMails virus scanner is great, the FortiSandbox will be able help detect and block 0 day viruses where no signature exists. 

     

    I'd also recommend looking at blocking password encrypted files. If your FortiMail cant decrypt it then it can't scan it. FYI there's a new feature with the latest version of FortiMail where it can use words in an email to try and decrypt files but I haven't tested it yet.

    TuncayBAS
    Explorer
    August 29, 2017

    In the IP Policies lines that are used, you can use the Antivirus profile.

    Malik
    MalikAuthor
    New Member
    August 29, 2017

    thank you for your replies.

    Neonbit, I will try to follow your recommendation.

     

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!