Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fjulianom
New Contributor III

Antivirus and flow-based full scan

Hi guys,

 

I have been reading about Antivirus with both inspection modes and had a doubt. I thought when using Antivirus with flow-based full scan only the IPS engine is used, but the NSE4 course says the following about Antivirus with flow-based full scan: "The IPS engine checks for the rule match and then sends to the AV engine for scanning".

Then, what is the exactly function of the IPS engine is the AV engine scans the file? What does rule match mean?

 

Thanks in advance,

Julián

1 Solution
tanr
Valued Contributor II

I think it's a little more complicated than that.

 

Life of a Packet http://docs.fortinet.com/uploaded/files/2795/fortigate-optimal-life-54.pdf on pages 20 and 22 show the flow-based and proxy-based inspection process -- or at least a rough outline of it.

 

There was some discussion of this a while back: https://forum.fortinet.com/tm.aspx?m=135666.

 

View solution in original post

1 REPLY 1
tanr
Valued Contributor II

I think it's a little more complicated than that.

 

Life of a Packet http://docs.fortinet.com/uploaded/files/2795/fortigate-optimal-life-54.pdf on pages 20 and 22 show the flow-based and proxy-based inspection process -- or at least a rough outline of it.

 

There was some discussion of this a while back: https://forum.fortinet.com/tm.aspx?m=135666.

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors