Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ederwindows98
New Contributor

Fortigate 60E - Configuring Antivirus - EICAR file test don't blocked

Hi!

I'm configuring the antivirus for first time in the Fortios 5.4.6. I follow this cookbook:

https://docs.fortinet.com/document/fortigate/5.4.0/cookbook/350705/inspecting-traffic-content-using-...

But when i test the configuration with the EICAR file test it don't block the download.

Here my screenshots of police:

Thank you everybody!

5 REPLIES 5
druber
New Contributor II

ederwindows98 wrote:

Hi!

I'm configuring the antivirus for first time in the Fortios 5.4.6. I follow this cookbook:

https://docs.fortinet.com/document/fortigate/5.4.0/cookbook/350705/inspecting-traffic-content-using-...

But when i test the configuration with the EICAR file test it don't block the download.

Here my screenshots of police:

Thank you everybody!

Same here.  I just purchased license for AV, and the GUI confirms I am licensed.  Yet, applying the AV profile as above, when I go to the eicar site, I am allowed to download anything there.  And the stats show:

 

gateway # diagnose ips av stats show AV stats: HTTP virus detected: 0 HTTP virus blocked: 0 SMTP virus detected: 0 SMTP virus blocked: 0 POP3 virus detected: 0 POP3 virus blocked: 0 IMAP virus detected: 0 IMAP virus blocked: 0 NNTP virus detected: 0 NNTP virus blocked: 0 FTP virus detected: 0 FTP virus blocked: 0 SMB virus detected: 0 SMB virus blocked: 0

Looking at that command makes me wonder: do I need IPS turned on for this?  The docs are extremely detailed about some things, but don't mention some pretty basic nuts and bolts.

druber
druber
Jirka1
Contributor III

Hi,

 

did you use this page? https://www.eicar.org/?page_id=3950 If so the download is via https only. In order to block the AV threat, you must have SSL deep inspection enabled. Jirka

druber
New Contributor II

yeah, crossing emails :)  thanks for confirming this...

druber
druber
druber
New Contributor II

Well, I'm stupid.  I hadn't really noticed the eicar site specifically disallows http, only allowing https, so of course fortinet can't find it.  I did find this: http://malware.wicar.org/data/eicar.com.  I copied the URL to the clipboard, and tried to access it using lynx, in a shell window, and:

High Security Alert    You are not permitted to download the file "eicar.com" because it is    infected with the virus "EICAR_TEST_FILE".    URL                   [link]http://malware.wicar.org/data/eicar.com[/link]    Quarantined File Name    Reference URL         [link]http://www.fortinet.com/ve?vn=EICAR_TEST_FILE[/link]

and printing av stats:

 

gateway # diagnose ips av stats show AV stats: HTTP virus detected: 1 HTTP virus blocked: 1 SMTP virus detected: 0 SMTP virus blocked: 0 POP3 virus detected: 0 POP3 virus blocked: 0 IMAP virus detected: 0 IMAP virus blocked: 0 NNTP virus detected: 0 NNTP virus blocked: 0 FTP virus detected: 0 FTP virus blocked: 0 SMB virus detected: 0 SMB virus blocked: 0

 

so, that's a big 'never mind folks' :)

 

 

druber
druber
ederwindows98
New Contributor

Thanks guy!

I'm newbie in the fortigate configurations.

In the ssl inspection profiles there are a deep-inspection profile.

But it doesn't show when I open the list in the Edit policy page.

I should enable it per cli?

 

 

 

Labels
Top Kudoed Authors