Hello!
I try to understand "Flow-based antivirus scanning order" - https://help.fortinet.com/fos60hlp/60/Content/FortiOS/fortigate-security-profiles/Antivirus/Antiviru...
"The following figure illustrates the antivirus scanning order when using flow-based scanning (i.e. the flow-based database). The antivirus scan takes place before any other antivirus-related scan. If file filter is not enabled, the file is not buffered."
but it the same time:
"FortiOS 5.2 introduced a new type of flow-based AV scanning, that is sometimes called deepflow or deep flow, and that takes a hybrid approach where content packets are buffered while simultaneously being sent to their destination. When all of the files packets have been collected and buffered, but before the final packet is delivered, the buffered file is scanned." - [link=https://help.fortinet.com/fos60hlp/60/Content/FortiOS/fortigate-security-profiles/Inspection%20Modes/antivirus_scanning_modes.htm]https://help.fortinet.com/fos60hlp/60/Content/FortiOS/fortigate-security-profiles/Inspection%20Modes/antivirusscanningmodes.htm[/link]
I think that figure that illustrates the Flow-based antivirus scanning order MUST has BUFFERING STAGE before AV scanning stage as during Proxy-based antivirus scanning order ....
So, my question -- Where is the correct scheme for Flow-based AV scanning order using deepflow ?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.