Fortinet white logo
Fortinet white logo

CLI Reference

config cifs profile

config cifs profile

Configure CIFS profile.

config cifs profile
    Description: Configure CIFS profile.
    edit <name>
        set domain-controller {string}
        config file-filter
            Description: File filter.
            set status [enable|disable]
            set log [enable|disable]
            config entries
                Description: File filter entries.
                edit <filter>
                    set comment {var-string}
                    set action [log|block]
                    set direction [incoming|outgoing|...]
                    set file-type <name1>, <name2>, ...
                next
            end
        end
        set server-credential-type [none|credential-replication|...]
        config server-keytab
            Description: Server keytab.
            edit <principal>
                set keytab {string}
            next
        end
    next
end

config cifs profile

Parameter

Description

Type

Size

domain-controller

Domain for which to decrypt CIFS traffic.

string

Maximum length: 255

name

Profile name.

string

Maximum length: 35

server-credential-type

CIFS server credential type.

option

-

Option

Description

none

Credential derivation not set.

credential-replication

Credential derived using Replication account on Domain Controller.

credential-keytab

Credential derived using server keytab.

config file-filter

Parameter

Description

Type

Size

status

Enable/disable file filter.

option

-

Option

Description

enable

Enable file filter.

disable

Disable file filter.

log

Enable/disable file filter logging.

option

-

Option

Description

enable

Enable file filter logging.

disable

Disable file filter logging.

config entries

Parameter

Description

Type

Size

filter

Add a file filter.

string

Maximum length: 35

comment

Comment.

var-string

Maximum length: 255

action

Action taken for matched file.

option

-

Option

Description

log

Allow the content and write a log message.

block

Block the content and write a log message.

direction

Match files transmitted in the session's originating or reply direction.

option

-

Option

Description

incoming

Match files transmitted in the session's originating direction.

outgoing

Match files transmitted in the session's reply direction.

any

Match files transmitted in the session's originating and reply direction.

file-type <name>

Select file type.

File type name.

string

Maximum length: 39

config server-keytab

Parameter

Description

Type

Size

principal

Service principal. For example, "host/cifsserver.example.com@example.com".

string

Maximum length: 511

keytab

Base64 encoded keytab file containing credential of the server.

string

Maximum length: 8191

config cifs profile

config cifs profile

Configure CIFS profile.

config cifs profile
    Description: Configure CIFS profile.
    edit <name>
        set domain-controller {string}
        config file-filter
            Description: File filter.
            set status [enable|disable]
            set log [enable|disable]
            config entries
                Description: File filter entries.
                edit <filter>
                    set comment {var-string}
                    set action [log|block]
                    set direction [incoming|outgoing|...]
                    set file-type <name1>, <name2>, ...
                next
            end
        end
        set server-credential-type [none|credential-replication|...]
        config server-keytab
            Description: Server keytab.
            edit <principal>
                set keytab {string}
            next
        end
    next
end

config cifs profile

Parameter

Description

Type

Size

domain-controller

Domain for which to decrypt CIFS traffic.

string

Maximum length: 255

name

Profile name.

string

Maximum length: 35

server-credential-type

CIFS server credential type.

option

-

Option

Description

none

Credential derivation not set.

credential-replication

Credential derived using Replication account on Domain Controller.

credential-keytab

Credential derived using server keytab.

config file-filter

Parameter

Description

Type

Size

status

Enable/disable file filter.

option

-

Option

Description

enable

Enable file filter.

disable

Disable file filter.

log

Enable/disable file filter logging.

option

-

Option

Description

enable

Enable file filter logging.

disable

Disable file filter logging.

config entries

Parameter

Description

Type

Size

filter

Add a file filter.

string

Maximum length: 35

comment

Comment.

var-string

Maximum length: 255

action

Action taken for matched file.

option

-

Option

Description

log

Allow the content and write a log message.

block

Block the content and write a log message.

direction

Match files transmitted in the session's originating or reply direction.

option

-

Option

Description

incoming

Match files transmitted in the session's originating direction.

outgoing

Match files transmitted in the session's reply direction.

any

Match files transmitted in the session's originating and reply direction.

file-type <name>

Select file type.

File type name.

string

Maximum length: 39

config server-keytab

Parameter

Description

Type

Size

principal

Service principal. For example, "host/cifsserver.example.com@example.com".

string

Maximum length: 511

keytab

Base64 encoded keytab file containing credential of the server.

string

Maximum length: 8191