Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

relation between oversized file and AV

Hi all, I' m confused with oversized file " " pass" and " block" , and anti virus function, if the action is Pass, then does AV check less than threshold amount or greater amount? or i' m wrong and something else would happen, it makes me nervous, Best, Kamyar
14 REPLIES 14
UkWizard
New Contributor

the file size if the maximum size that the AV will scan. so if you are downloading a 11MB file, and you have it set to 10MB, then it will allow it through unscanned if it is set to ' pass' . if its set to block, it will not allow you to download a file thats bigger than the setting, so this 11MB file would be blocked.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

" the file size if the maximum size that the AV will scan. so if you are downloading a 11MB file, and you have it set to 10MB, then it will allow it through unscanned if it is set to ' pass' . " and the AV does not check the first 10 MB? Best, Kamyar
Secure_IT_BE_Nick
New Contributor III

That was also my idea. Looking for more info on that. Nick

[link]https://www.secure-it.be[/link]

[link]https://www.secure-it.be[/link]
doshbass
New Contributor III

The AV will not check any of a large file. Fortinet AV works by buffering the file and then performing AV functions. If the file is too large, according to threshold, or larger that 2/3rds (I think) of the limit when compressed. It will bypass AV and the action selected will occur. To scan part of the file is not the Fortinet way as this implies stream based AV,which is little more than IPS. The Fortigate AV is considerably more advanced than this, and includes teh ability to uncompress GZIP files and identify custom unpackers etc. Check out http://blog.fortinet.com for some real in depth AV stuff
Still learning to type " the"
Still learning to type " the"
UkWizard

Doshbass, I think it actually depends on the way the file is served, if the file size is provided back to the client (and thus also the firewall), then it seems to see its too big and bypass the AV scanning. If the size isnt reported (which seems to be case most of the time) then it does scan the file up to the threshold. At least, this is what i see when i test it.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Eastwind

ORIGINAL: UkWizard Doshbass, I think it actually depends on the way the file is served, if the file size is provided back to the client (and thus also the firewall), then it seems to see its too big and bypass the AV scanning. If the size isnt reported (which seems to be case most of the time) then it does scan the file up to the threshold. At least, this is what i see when i test it.
Hi UK Wizard, what is the benefit of scan the file up to the threshold? can virus be embedded anywhere in pdf or in any files, like start, middle or end of the file or in attachement? A lot of files or patches that we have to download are way larger than the threshold 12MB, what do u suggest ? is OS 4.0 better in scanning larger file that is scalable.
doshbass
New Contributor III

I guess it may buffer, getting ready to scan, but it will not actually begin scanning until teh entire file is downloaded. So in the case of oversized file without a known size, then buffer buffer buffer buffer too big give. Only in 1s and 0s Oh and call me Dosh, tha bass bit is just a fomality
Still learning to type " the"
Still learning to type " the"
Not applicable

and can i increase the treshold amount (by default %10 RAM)? if so, how many do you recommend? Best, kamyar
Secure_IT_BE_Nick
New Contributor III

Just did the test.. Downloaded file of 15 mb, first 10mb download at 4mb/sec. then it drops to the speed of internet. Thus it' s scanning the first 10meg and then passes the rest.

[link]https://www.secure-it.be[/link]

[link]https://www.secure-it.be[/link]
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors