FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
bkarl
Staff
Staff
Article Id 272891
Description

This article describes the correct way to combine File Filter and Antivirus profile to avoid EICAR malicious file access.

Scope FortiGate v7.4.0.
Solution
  1. Make sure to have a firewall policy set on proxy inspection mode, the Antivirus profile and File Filter are set on proxy mode.
  2. Make sure to have the firewall operating in profile mode.
  3. In this example, default profile and Deep inspection are enabled.
  4. Do not forget to install certificate CA on the PC to protect it.
  5. It is possible to test with Eicar's anti-malware test file.
  6. Download any of the following files and a blocking message like this one will appear:

 

KB 22 - 1.jpg

 

KB 22 - 2.jpg


date=2025-09-25 time=02:57:49 eventtime=1758794268860360434 tz="-0700" logid="0211008192" type="utm" subtype="virus" eventtype="infected" level="warning" vd="root" policyid=8 poluuid="acfe8828-564c-51f0-9e45-c451ae68d1de" policytype="policy" msg="File is infected." action="blocked" service="HTTPS" sessionid=354536291 srcip=10.187.17.245 dstip=89.238.73.97 srcport=55914 dstport=443 srccountry="Reserved" dstcountry="Germany" srcintf="port4" srcintfrole="undefined" dstintf="port1" dstintfrole="undefined" srcuuid="d42df33a-2f13-51f0-b7cf-b3cd98be54d3" dstuuid="d42df33a-2f13-51f0-b7cf-b3cd98be54d3" proto=6 direction="incoming" filename="eicarcom2.zip" quarskip="Quarantine-disabled" virus="EICAR_TEST_FILE" viruscat="Virus" dtype="av-engine" ref="https://fortiguard.com/encyclopedia/virus/2172" virusid=2172 url="https://secure.eicar.org/eicarcom2.zip" profile="default" agent="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36" httpmethod="GET" referralurl="https://www.eicar.org/" analyticscksum="e1105070ba828007508566e28a2b8d4c65d192e9eaf3b7868382b7cae747b397" analyticssubmit="false" crscore=50 craction=2 crlevel="critical"

 

To install certificate Fortinet_CA_SSL:

'Double-click' on the .cert file, select the Install option -> Local PC/Device, place all certificates on the following store, choose the second folder, select next, and then, select 'Finish'.

 

KB 22 - 4.jpg

 

KB 22 - 3.jpg

 

Related documents: