FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
dingjerry_FTNT
Article Id 424225
Description This article explains why the FortiGate stops sending files to FortiSandbox for inspection after upgrading from a version prior to 7.2.0 GA to 7.2.0 GA or later.
Scope FortiOS 7.2.0 GA+. All FortiGate models.
Solution

After upgrading the FortiGate device from a version prior to 7.2.0 GA (i.e., 7.0.18 GA) to 7.2.0 GA or later, if FortiSandbox is configured in an Antivirus profile for file inspection, the FortiGate will stop sending files to FortiSandbox for inspection.

 

Root cause:

Prior to FortiOS 7.2.0 GA, the Antivirus profile had the following configuration:

 

AV_old.png

 

The configuration of 'Send Files to FortiSandbox for Inspection' is explicit.

 

After FortiOS 7.2.0 GA and later, it has been changed to the following:

 

AV_New.png

 

The 'Send Files to FortiSandbox for Inspection' configuration has a switch button now.

 

After upgrading to FortiOS 7.2.0 GA or later from a version before 7.2.0 GA, this switch button is disabled even if the FortiSandbox has already been provisioned in this Antivirus profile. 

 

This switch button has to be turned on to restore FortiSandbox file inspection.