Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
gbaharoff
New Contributor

IP Address Fortishield Check

I have FortiOS 2.80 MR6 and noticed a new setting within the Protection Profile under SPAM Filtering labeled IP Address Fortishield Check. I read the online help, but it doesn' t mention Fortishield, but FortiEguard (Yes with an E). I went to the Fortinet site and found nothing on the FortiShield or FortiEguard (Yes with an E). Obviously I found information regarding the Category Blocking service Fortiguard (Without an E). Does anybody have any information regarding either the Fortishield or FortiEguard?
Greg Baharoff Fortinet Certified System Engineer MTBW Services, Inc. 327 E Ridgeville Blvd 154 Mount Airy MD 21771 301-829-5925
Greg Baharoff Fortinet Certified System Engineer MTBW Services, Inc. 327 E Ridgeville Blvd 154 Mount Airy MD 21771 301-829-5925
10 REPLIES 10
Alex_Libenson
New Contributor

FortiShield is RBL/ORDB-like service provided by Fortinet. Still not sure if it will be available by subscription only as FortiGuard or free, but currently it is free. According to FortiOS 2.80 MR6 release notes: 3.7.2 FortiShield Anti-Spam subscription support Description: FortiShield Anti-Spam is a new subscription service for providing Anti-Spam Definitions (initially DNSBL or DNS-based black lists) updates through the FortiShield servers is now supported from MR4 and later. This service will be activated later in 2004-Q4. (Note: Port UDP/8889 is used by the FortiGate unit to communicate with the FortiShield servers and may require further configuration of other upstream firewalls.)
gbaharoff
New Contributor

Thanks Alex. I wonder what benefit that will have over some of the more established RBL' s.
Greg Baharoff Fortinet Certified System Engineer MTBW Services, Inc. 327 E Ridgeville Blvd 154 Mount Airy MD 21771 301-829-5925
Greg Baharoff Fortinet Certified System Engineer MTBW Services, Inc. 327 E Ridgeville Blvd 154 Mount Airy MD 21771 301-829-5925
Not applicable

Hi, FortiShield is a Spam Prevention based on Heuristics Method . This is more stable and reliable as compared to RBL/ORDB servers . This will give less False positives and almost all the Antispam servers used in todays market uses Heuristics Method and achieve upto 97% Spam prevention if configured properly.
Not applicable

Where can I find more information on fortishield spam blocking?
Not applicable

I' m also very interested in this new feature but indeed information is limited. I' m currently planning the roll-out of SpamAssassin as a mail gateway because the current Anti-Spam protection of my Fortigate is to little, but that could be not necessary when this FortiShield services does (almost) the same. So anybody any good advice where I can find more information?
Not applicable

We have been testing it for 2 weeks. And it works quite good. But this week a customer called us that he was unable to send us mail. So I started to look in the antispam logs, and I found that: the mail was blocked because it was listed on the fortishield blacklist. I wanted to check why my customer is on this blacklist but I can' t find anything about this blacklist, I don' t know wher to consult this blacklist (as you can do with all (o)rbl) I also don' t know how my customer can start a request for removal. Does somebody know this??? Thanks in advance Kristof
Not applicable

kristof: take a look at here http://www.nospammer.net/ this link is mentioned in 2.8 MR8 release notes beat
Not applicable

Thanks Mister Bee They were indeed listed on that site, altought they do not realy tell why they are listed. Most RBL' s ORBL' s are giving an explanation. for example: They don' t hav a PTR record (reverse lookup address), or It' s a open relay etc Kristof
GTNman
New Contributor

I turned this feature on last night on my FGT-100, only to find 95% of all e-mail tagged as spam in the morning. I was using this tag in conjunction w/ two RBL/ORDB servers. Has anyone else experienced this type of phenomena?
Labels
Top Kudoed Authors