Hello all,
I am running firmware 5.2.8
what the benefit and impact of enable "heuristic quarantine" in Antivirus profile?
What do I need to do it?
Thanks
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello CAD,
maybe you could try to read the admin guide before asking these kind of questions (Handbook 5.4, Page 2112), or is this information not enough for you?:
Heuristics After an incoming file has passed the grayware scan, it is subjected to the heuristics scan. The FortiGate heuristic antivirus engine, if enabled, performs tests on the file to detect virus-like behavior or known virus indicators. In this way, heuristic scanning may detect new viruses, but may also produce some false positive results. You configure heuristics from the CLI. To set heuristics, enter the following in the CLI: config antivirus heuristic set mode {pass |block |disable} end l “block” enables heuristics and any files determined to be malware are blocked from entering the network. l “pass” enables heuristics but any files determined to be malware are still allowed to pass through to the recipient. l “disable” turns off heuristics.
Any insight ?
any advise please?
Hello CAD,
maybe you could try to read the admin guide before asking these kind of questions (Handbook 5.4, Page 2112), or is this information not enough for you?:
Heuristics After an incoming file has passed the grayware scan, it is subjected to the heuristics scan. The FortiGate heuristic antivirus engine, if enabled, performs tests on the file to detect virus-like behavior or known virus indicators. In this way, heuristic scanning may detect new viruses, but may also produce some false positive results. You configure heuristics from the CLI. To set heuristics, enter the following in the CLI: config antivirus heuristic set mode {pass |block |disable} end l “block” enables heuristics and any files determined to be malware are blocked from entering the network. l “pass” enables heuristics but any files determined to be malware are still allowed to pass through to the recipient. l “disable” turns off heuristics.
Thanks for response and for this information.
Word. Handbook is a one stop shop for TONS of FortiGate / FortiOS information. The heuristics scanner can come in handy depending on the application and placement of the Gate in the network.
Mike Pruett
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.