Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
CAD
Contributor

enable heuristic&quarantine

Hello all,

I am running firmware 5.2.8

 

what the benefit and impact of enable "heuristic quarantine" in Antivirus profile?

What do I need to do it?

 

Thanks

1 Solution
oheigl
Contributor II

Hello CAD,

 

maybe you could try to read the admin guide before asking these kind of questions (Handbook 5.4, Page 2112), or is this information not enough for you?:

 

Heuristics After an incoming file has passed the grayware scan, it is subjected to the heuristics scan. The FortiGate heuristic antivirus engine, if enabled, performs tests on the file to detect virus-like behavior or known virus indicators. In this way, heuristic scanning may detect new viruses, but may also produce some false positive results. You configure heuristics from the CLI. To set heuristics, enter the following in the CLI: config antivirus heuristic set mode {pass |block |disable} end l “block” enables heuristics and any files determined to be malware are blocked from entering the network. l “pass” enables heuristics but any files determined to be malware are still allowed to pass through to the recipient. l “disable” turns off heuristics.

View solution in original post

5 REPLIES 5
CAD
Contributor

Any insight ?

CAD
Contributor

any advise please?

oheigl
Contributor II

Hello CAD,

 

maybe you could try to read the admin guide before asking these kind of questions (Handbook 5.4, Page 2112), or is this information not enough for you?:

 

Heuristics After an incoming file has passed the grayware scan, it is subjected to the heuristics scan. The FortiGate heuristic antivirus engine, if enabled, performs tests on the file to detect virus-like behavior or known virus indicators. In this way, heuristic scanning may detect new viruses, but may also produce some false positive results. You configure heuristics from the CLI. To set heuristics, enter the following in the CLI: config antivirus heuristic set mode {pass |block |disable} end l “block” enables heuristics and any files determined to be malware are blocked from entering the network. l “pass” enables heuristics but any files determined to be malware are still allowed to pass through to the recipient. l “disable” turns off heuristics.

CAD

Thanks for response and for this information.

MikePruett
Valued Contributor

Word. Handbook is a one stop shop for TONS of FortiGate / FortiOS information. The heuristics scanner can come in handy depending on the application and placement of the Gate in the network.

Mike Pruett Fortinet GURU | Fortinet Training Videos
Labels
Top Kudoed Authors