FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
rain
Staff
Staff
Article Id 385058
Description This article describes how to view and audit the files being scanned and classified by FortiSanbox on FortiGate Cloud.
Scope FortiGate using Inline Scanning to FortiSandbox (FortiGate Cloud).
Solution

When using an Inline antivirus scan to FortiSanbox on FortiGate Cloud, it is important to consider that these logs are going to be seen on the Security events on the Fortigate at Antivirus section, and that the main platform and dashboard to see the file being scanned by the inline profile and sent to FortiSandbox is 'FortiGate Cloud'.

 

SANDBOX01.png

 

This is a log from the blocked virus file on the FortiGate. Can be identified by the 'inline-block' description type and also by the message 'Blocked by inline block'.

 

In order to see the complete logs of all the files being scanned by the Inline scan and sent to FortiSandbox, follow these steps:

 

 

SANDBOX02.png

 

  • On the FortiGate Cloud Platform, go to Sandbox -> Scan results.

 

SANDBOX03.png

 

  • Once there, on this section will be shown all the files being scanned by FortiSandbox Inline configuration on the FortiGate, being categorized by Clean files (non-virus files), Risk (files compromised and categorized as malicious), and Pending (Files on scan state and waiting to be classified).

 

SANDBOX04.png

Contributors