Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
usmansa1
New Contributor II

Questions regarding antivirus profile ?

Hi, 

 

I was reading the FortiGate antivirus topic from Fortinet website. Also I tested them in my test environment by downloading the file from ecior.org. What I found, until or unless you don't use SSL/SSH decryption profile, this antivirus profile is  helpless which means that unless or until we don't do the SSL decryption the encrypted files cant be scanned. Is this correct assumption ? Moreover, can any one please help me to point in right direction that where can I find more information about CPRL ?

1 REPLY 1
akileshc
Staff
Staff

Hello, 

Yes, your understanding is correct. In order for the FortiGate antivirus profile to scan encrypted files, SSL/SSH decryption must be enabled to decrypt the traffic for inspection. Without decryption, the antivirus profile cannot scan encrypted files for viruses and malware.

You can access the FortiOS documents to understand the requirement and test cases:

https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/315155/testing-an-antivirus-... 

 https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/122078/deep-inspection

Akilesh
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors