Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Malik
New Contributor III

Is it normal to receive too much threat/viruses?

Hi,

 

In my fortimail log (installed in fortimanager) I can find so many threat/viruses, like 1 email with infected file each 2 or 10 Seconds.

 

With dynamic sources (Majority asia). What I want to know, if you are experiencing the same events in your fortimail? And what are some best practice to reinforce my fortimail and security in general? (I have only fortinet product for security)

 

Thank you for your answers.

 

 

1 Solution
neonbit
Valued Contributor

I sometimes see floods like that when there's a virus outbreak.

 

My biggest recommendation to reinforce your FortiMail is to get FortiSandbox (either cloud service or local appliance). While the FortiMails virus scanner is great, the FortiSandbox will be able help detect and block 0 day viruses where no signature exists. 

 

I'd also recommend looking at blocking password encrypted files. If your FortiMail cant decrypt it then it can't scan it. FYI there's a new feature with the latest version of FortiMail where it can use words in an email to try and decrypt files but I haven't tested it yet.

View solution in original post

4 REPLIES 4
neonbit
Valued Contributor

I sometimes see floods like that when there's a virus outbreak.

 

My biggest recommendation to reinforce your FortiMail is to get FortiSandbox (either cloud service or local appliance). While the FortiMails virus scanner is great, the FortiSandbox will be able help detect and block 0 day viruses where no signature exists. 

 

I'd also recommend looking at blocking password encrypted files. If your FortiMail cant decrypt it then it can't scan it. FYI there's a new feature with the latest version of FortiMail where it can use words in an email to try and decrypt files but I haven't tested it yet.

TuncayBAS

In the IP Policies lines that are used, you can use the Antivirus profile.

Tuncay BAS RZK Muhendislik Turkey NSE 4 5 6 FCESP v5

Tuncay BAS RZK Muhendislik Turkey NSE 4 5 6 FCESP v5
Malik
New Contributor III

thank you for your replies.

Neonbit, I will try to follow your recommendation.

 

 

Carl_Windsor_FTNT

There are some important features added to FortiMail in recent releases to help with this type of outbreak:

 

Malware Outbreak (>5.2): Data analytics on queries to FortiGuard to identify potential threats

Virus Outbreak:(>5.4): Virus outbreak service real-time list of threat hashes for new outbreaks detected from multiple sources.

 

Ensure that you are using Malware Outbreak, ensure the FortiGuard lookup cache is not set too high and consider upgrading to 5.4 and trying out Virus Outbreak (licensed feature) as both are giving great outbreak protection.

 

Dr. Carl Windsor Field Chief Technology Officer Fortinet

Labels
Top Kudoed Authors