Description | This article describes how to enable Sandboxing in FortiSASE. |
Scope | FortiSASE, Sandboxing. |
Solution |
FortiSASE includes an integrated Sandbox engine hosted in the cloud, orchestrated through the FortiSASE console. However, its enforcement occurs locally on the endpoint through the FortiClient agent.
Go to Configuration -> Profile -> Default -> the Sandbox tab and select the 'FortiSASE' option for sandbox mode to enable a built-in sandbox engine.
Configure the options as shown below:
Verification:
Each time a new file with an unfamiliar signature is downloaded, FortiClient will initiate a file submission to the FortiSASE Sandbox engine. As depicted below, return to FortiClient and access the 'SANDBOX DETECTION' tab to confirm that the file has been submitted. Its initial verdict will be in a pending state until the cloud engine completes the sandbox process.
In the interim, while the file is under examination and its verdict remains unknown, opening or executing the file should be restricted. To confirm, locate the file in the file explorer and attempt to double-click on it; an error message should appear.
After a few minutes, FortiClient should receive the file verdict from the Sandbox engine and apply the configured action, as shown in the example below.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.