FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
nathan_h
Staff
Staff
Article Id 284495
Description

 

This article describes how to delete quarantined files on FortiGate. 

 

Scope

 

FortiGate.

 

Solution

 

Firewall policy with AntiVirus Profile configured:


config firewall policy

edit 22

set name "AV"
set uuid 321929be-83d6-51ee-1ac9-878b3c062155
set srcintf "port2"
set dstintf "port1"
set action accept
set srcaddr "all"
set dstaddr "all"
set schedule "always"
set service "ALL"
set utm-status enable
set ssl-ssh-profile "CustomDeep"
set av-profile "TEST_AV"
set logtraffic all
set nat enable

next

end

 

config antivirus profile

edit "TEST_AV"

set comment "Scan files and block viruses."

config http

set av-scan block
set quarantine enable

end

next

end

 

View the quarantined files on FortiGate:

 

diag antivirus quarantine list
Quarantine List (Count = 1)
-----------------------------
CHECKSUM SIZE FIRST-TIMESTAMP LAST-TIMESTAMP SERVICE STATUS DC TTL FILENAME DESCRIPTION
6851cf3c 68 2023-11-15 12:29 2023-11-15 12:29 HTTPS Infected 0 FOREVER 'eicar.com' 'EICAR_TEST_FILE'

 

 

Delete the quarantined files on FortiGate:

 

diag antivirus quarantine delete 6851cf3c

diag antivirus quarantine list
Quarantine List (Count = 0)
-----------------------------
CHECKSUM SIZE FIRST-TIMESTAMP LAST-TIMESTAMP SERVICE STATUS DC TTL FILENAME DESCRIPTION

Contributors