Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Fortishield Effective

Hi...we are in the process of evaluating Fortishield (as many appear to be) and I had a couple of basic questions (hopefully) a) Does the Fortishield simply discard the spam, or tag it?? b) If you are using Fortishield should you disable all other methods (since the fortishield is doing all the work) c) We have a number of scenarios where the mail servers (smtp and pop) are hosted externally outside of the fortigate unit..will fortishield still work?? Thanks!!
15 REPLIES 15
Don_Draper
New Contributor

New user on a Fortigate 200A-HD 2.8 MR8. So for I am a bit dissappointed in the SPAM and AV stuff. Viruses show up in the Fortigate logs but still reach our servers and workstations. What could I be doing wrong here? I thought the Fortigate would be smart enough to block attachments with viruses in them and let other attachment go through safely. Is this assumption incorrect? Banned words in emails result in SMTP session getting blocked. But look at the log and it tells it got blocked but there no way to know which banned word rule caused the block. I would think this would have been added long ago. How can I adjust my blocked words list when I have no idea which one caused the block? Surely I am green and just do not have it configured properly...right?
Don Draper
Don Draper
rb400

you will learn to live with this and other FGT disappointments...Fortinet numbness is your friend...repeat after me........

 

[align=left]*auto-sig*   rb400 << FGT (v6.2.x) [/align]
[align=left]*auto-sig* rb400 << FGT (v6.2.x) [/align]
Not applicable

Giggle, I too am a nooblet when it comes to the FGTs but it was pretty simple to find out that you typically are not even blocking the viruses if your protection profile isn' t using this feature or you use the wrong protection profile in the wrong policy. Pretty simple stuff. I slapped about 12 of these into various networks and my antivirus disinfections on my email servers went from 200-600/hr to about 15 a week. If you read the FTG whitepaper on how AV works, what a " zoo" virus is and how FGTs are so fast you will see that the best AV solutions is a blended one. I may be a noob but this stuff here is da bomb! Spend about 30-60 minutes reading the white papers and the tech manuals and you are good to go. Good luck and I hope you pay no attention to the other guy that replied, he' s definately technically challenged! I' m not the kind of guy that gets stuck on double-consonant, I realize some people need me to talk slow. JB
Don_Draper
New Contributor

I created my own custom protection profile and made sure all the right services use it such as POP, SMTP, FTP and HTTP. Fortinet will log the virus but my Symantec on the servers also see them and quaranteen the file. It also appears to think most any ZIP file as the " Suspicious" virus in it (even files on our server that users download via HTTP). Heck, I recently updated Windows Server 2000 with security updates and it tagged all of those files as having " Suspicious" virus as well. Any idea what I could be doing wrong here?
Don Draper
Don Draper
Not applicable

The heuristic scanner detects most binary executables (even those inside zip files) as ' suspicious' . You can disable heuristic scanning via the CLI like this:- fg # conf antivirus heuristic (heuristic)# set mode disable (heuristic)# end
Not applicable

Hi there! We have just did a research" at one university FortiShield (RBL and URL checking) effectiveness vs Symantec AntiSpam solution 2005 (NIS2005), after two weeks of testing simultaniously both AntiSpam sollutions on few very spammed mail_boxes the results are: Spam recieved on 20050503-20050518 1. Inbox_SPAM (FGT60 only tags) 368 2. Inbox_SPAM (NIS2005+FGT60 tags) 635 3. Inbox_SPAM (NIS2005 only tags) 48 4. Inbox_SPAM (nobody tags) 86 5. Inbox_SPAM (FGT60 false positive) 7 6. Inbox_SPAM (NIS2005 false positive) 82 7. Inbox_SPAM (FGT60 tagged at all) 1003 8. Inbox_SPAM (NIS2005 tagged at all) 683 9. Inbox_SPAM (total spam) 1226 And the results are: FGT60 - found ~82 % of SPAM; NIS2005 - found ~56 % of SPAM. I would say not bad
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors