NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
What netmin has posted is more in line with 4.0. MR3 (which I am more familiar with).Under 4.0. MR3, that section looks like this...
 config firewall profile-protocol-options
     edit " default" 
         set comment " all default services" 
             config http
                 set port 80 
                 set options clientcomfort
                 set comfort-amount 100
                 unset post-lang
                 set oversize-limit 5
             end
             config https
                 set port 443 
                 unset options
             end
             config ftp
                 set port 21 
                 set options no-content-summary splice
                 set oversize-limit 5
             end
             config imap
                 set port 143 
                 set options fragmail no-content-summary
                 set oversize-limit 5
             end
             config pop3
                 set port 110 
                 set options fragmail no-content-summary
                 set oversize-limit 5
             end
             config smtp
                 set port 25 
                 set options fragmail no-content-summary splice
                 set oversize-limit 5
             end
             config nntp
                 set port 119 
                 set options no-content-summary splice
                 set oversize-limit 5
             end
             config im
                 unset options
                 set oversize-limit 5
             end
     next
 end
 
 Under 5.0, tried to edit " default"  and add " set oversize-log disable"  but just gives me an error.  Only options I can set under " default"  is
 (default) # set comment comment replacemsg-group Replacement message group. extended-utm-log Enable/disable detailed UTM log messages.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
 FGT (default) # show full-configuration 
 
 config firewall profile-protocol-options
     edit " default" 
         set comment " all default services" 
         set replacemsg-group ' ' 
         set oversize-log disable
         set switching-protocols-log disable
             config http
                 set ports 80
                 set status enable
                 set inspect-all disable
                 set options clientcomfort no-content-summary
                 set comfort-interval 10
                 set comfort-amount 1
                 unset post-lang
                 set fortinet-bar disable
                 set streaming-content-bypass enable
                 set switching-protocols bypass
                 set oversize-limit 10
                 set retry-count 0
             end
             config ftp
                 set ports 21
                 set status enable
                 set inspect-all disable
                 set options clientcomfort no-content-summary splice
                 set comfort-interval 10
                 set comfort-amount 1
                 set oversize-limit 10
             end
             config imap
                 set ports 143
                 set status enable
 
                 set inspect-all disable
                 set options fragmail
                 set oversize-limit 10
             end
             config mapi
                 set ports 135
                 set status enable
                 set options fragmail no-content-summary
                 set oversize-limit 10
             end
             config pop3
                 set ports 110
                 set status enable
                 set inspect-all disable
                 set options fragmail no-content-summary
                 set oversize-limit 10
             end
             config smtp
                 set ports 25
                 set status enable
                 set inspect-all disable
                 set options fragmail no-content-summary splice
                 set oversize-limit 10
                 set server-busy disable
             end
             config nntp
                 set ports 119
                 set status enable
                 set inspect-all disable
                 set options no-content-summary splice
                 set oversize-limit 10
             end
 
             config dns
                 set ports 53
                 set status enable
             end
             config mail-signature
                 set status disable
                 set signature ' ' 
             end
     next
 end
 
 and a screenshot:
 
 
 
 
  
					
				
			
			
				
			
			
				
			
			
			
			
			
			
		profile=" Forsyth Protocol Options"- this one has oversize logging disabled as well?
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2711 | |
| 1416 | |
| 810 | |
| 727 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.