NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
What netmin has posted is more in line with 4.0. MR3 (which I am more familiar with).Under 4.0. MR3, that section looks like this...
config firewall profile-protocol-options
edit " default"
set comment " all default services"
config http
set port 80
set options clientcomfort
set comfort-amount 100
unset post-lang
set oversize-limit 5
end
config https
set port 443
unset options
end
config ftp
set port 21
set options no-content-summary splice
set oversize-limit 5
end
config imap
set port 143
set options fragmail no-content-summary
set oversize-limit 5
end
config pop3
set port 110
set options fragmail no-content-summary
set oversize-limit 5
end
config smtp
set port 25
set options fragmail no-content-summary splice
set oversize-limit 5
end
config nntp
set port 119
set options no-content-summary splice
set oversize-limit 5
end
config im
unset options
set oversize-limit 5
end
next
end
Under 5.0, tried to edit " default" and add " set oversize-log disable" but just gives me an error. Only options I can set under " default" is
(default) # set comment comment replacemsg-group Replacement message group. extended-utm-log Enable/disable detailed UTM log messages.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
FGT (default) # show full-configuration
config firewall profile-protocol-options
edit " default"
set comment " all default services"
set replacemsg-group ' '
set oversize-log disable
set switching-protocols-log disable
config http
set ports 80
set status enable
set inspect-all disable
set options clientcomfort no-content-summary
set comfort-interval 10
set comfort-amount 1
unset post-lang
set fortinet-bar disable
set streaming-content-bypass enable
set switching-protocols bypass
set oversize-limit 10
set retry-count 0
end
config ftp
set ports 21
set status enable
set inspect-all disable
set options clientcomfort no-content-summary splice
set comfort-interval 10
set comfort-amount 1
set oversize-limit 10
end
config imap
set ports 143
set status enable
set inspect-all disable
set options fragmail
set oversize-limit 10
end
config mapi
set ports 135
set status enable
set options fragmail no-content-summary
set oversize-limit 10
end
config pop3
set ports 110
set status enable
set inspect-all disable
set options fragmail no-content-summary
set oversize-limit 10
end
config smtp
set ports 25
set status enable
set inspect-all disable
set options fragmail no-content-summary splice
set oversize-limit 10
set server-busy disable
end
config nntp
set ports 119
set status enable
set inspect-all disable
set options no-content-summary splice
set oversize-limit 10
end
config dns
set ports 53
set status enable
end
config mail-signature
set status disable
set signature ' '
end
next
end
and a screenshot:
profile=" Forsyth Protocol Options"- this one has oversize logging disabled as well?
| User | Count |
|---|---|
| 2691 | |
| 1412 | |
| 810 | |
| 709 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.