I saw this "new" license option on Fortimail OS 5.4, however i cannot find any documentation online about how it works exactly and how it differs from regular antivirus which is already licensed
Anyone have any idea?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
FortiGuard Virus Outbreak Protection Service provides several additional layers of protection in addition to the existing FortiGuard AV:
[ul]We had previously used this service internally to identify new samples for introduction into the AV engine however, due to the nature of email where the risk of false positive is lower than e.g on a desktop (files can just be quarantined rather than potentially disrupting the OS), we can afford to be more aggressive with our detection and block these suspected threats in real-time before AV signatures are available. We have seen that this service is providing a valuable additional level of protection above normal AV at times of a new, previously unknown outbreak.
Dr. Carl Windsor Field Chief Technology Officer Fortinet
Hi there,
thanks for the explanation but makes this any sense if i have a fortisandbox cloud service already?
Regards
sudo apt-get-rekt
Absolutely. This check is almost instant like our AV check. It is better to stop threats quickly without loading the FortiSandbox which may take several minutes to queue and explode and detect in the sandbox.
Dr. Carl Windsor Field Chief Technology Officer Fortinet
Sounds Good, but if there is any Reference to explain those 4 Benefits in more details, things will be more clear.
Hi!
I have two questions about this topic:
1. When customers migrate from FortiOS 5.4 to FortiOS 6.0, do they automatically have VOS and CDR activated if they had purchased Enterprise Bundle?
2. How does the VOS service defines which files will be hashed for sending their hash to FortiSandbox cloud? Doest FortiGate sends a hash of all the files to FortiSandbox cloud?
Many thanks
Rodrigo
1.. If the customer purchased the enterprise bundle in Q2 and have been running this since with 5.4, yes when the upgrade they will get VOS and CDR on upgrade.
2. The VOS scan happens before the FortiSandbox scan and will rate the file as unknow or bad. This scan does not impact whether the file gets sent to the Sandbox unless it is a known bad sample and is therefore blocked.
Dr. Carl Windsor Field Chief Technology Officer Fortinet
Apologies for returning to this topic late. I find hard to get information about activating this service. According to what you explained in your previous post, the service is not included in the BDL for those who purchased or renewed FortiGuard services before Q2'18, right? Why Fortinet provide services outside the BDL? Thanks in advance
>the service is not included in the BDL for those who purchased or renewed FortiGuard services before Q2'18, right?
Correct. You can check whether this is included in your license by logging into FortiCare and looking for the FortiGuard Virus Outbreak Protection Service entitlement.
>Why Fortinet provide services outside the BDL?
It was a newly added feature so it wasn't part of the bundle. In Q2, we created new base and enterprise and included this entitlement in both.
For pre-Q2 without this entitlement, it can be added a la carte with the 150 SKU e.g. for the FML 200E
FC-10-FE20E-150-02-DDFortiGuard Virus Outbreak Protection Service
Dr. Carl Windsor Field Chief Technology Officer Fortinet
I understand, but it seems not to be 100% clear for Fortinet TAC. I work as a product manager on a enterprise which is Fortinet Gold Partner. In Q4 price list, the BDL does include the VOS service:
Hardware plus 24x7 FortiCare and FortiGuard Base Bundle
Hardware Unit, Advanced Hardware Replacement (NBD), Firmware and General Upgrades, 24x7 FortiCare Support, FortiGuard AS & AV, FortiGuard Virus Outbreak Protection, FortiSandbox Cloud, Click Protect (FECP), Content Disarm & Reconstruction, Business Email Compromise, Identity Based Encryption, Data Loss Prevention, Archiving plus term of contract
Also if you read pag. 8 from this article: https://docs.fortinet.com/uploaded/files/4445/fortimail-v6.0.0-release-notes.pdf it says that the service should be included on basic BDL.
Just to be clear, I'm not trying to convence you, but I'm having different answers from Fortinet, some says it's included, others says it's not.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.