Hi!
The current Fortigates offer the feature "Use FortiSandbox Database" in AV-profiles.
Is there any difference on that feature depending on:
- Using FortiSandbox Cloud
- Using FortiSandbox On-Prem
- Non of both?
--> Are the pattern, that are detected on any "sharing" Fortisandbox directly pushed to the Fortiguard-Updates, are there differences according to the rest of the FortiSandbox-usage?
Thank you for your help!
KPS
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
If you're referring to the database of samples collected from Fortisandboxes around the world then no, it is the same Fortiguard database referenced in the cloud query engine in FortiSandbox.
If you're referring to the database of samples collected from Fortisandboxes around the world then no, it is the same Fortiguard database referenced in the cloud query engine in FortiSandbox.
There are differences, of course.
(disclaimer: as far as I have understood...)
1- FSA Cloud
Positive results are added to the regular, worldwide FortiGuard AV database, and thus eventually distributed to your FGT. To minimize delay, enable "push updates".
2- FSA on premise
Positive results lead to the creation of an AV signature update which is offered immediately on your local network. Devices have to subscribe to these updates. Optionally, the updates are added to the regular, worldwide FortiGuard AV database.
Fortigates in your network may actively submit files to the local FSA, or just participate in the FSA updates. This way, only the main firewalls and FortiMail submit files (to conserve FSA resources) but all Fortinet devices profit from the findings.
3- neither FSA Cloud subscription nor on premise
You get the regular FortiGuard AV updates, i.e., the switch is not effective.
I think for virus outbreak fortiguard has to validate the sample submitted b4 they are provided as a globally supplied signature.
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.