Fortinet black logo

Cookbook

Creating an AntiVirus profile

Creating an AntiVirus profile

  1. Go to Profile > AntiVirus > AntiVirus and click New.
  2. Assign a specific Domain if necessary, otherwise leave it as a System based profile.
  3. Enter a Profile name.
  4. Set Default action to an antivirus action profile. For this example, set to SystemQuarantine.
  5. Note that, in this case, if you set Default action to Reject, the actual action taken will be to fallback to system quarantine, since email messages are to be sent to the FortiSandbox unit.

  6. Under FortiSandbox, set the default Scan mode: Submit and wait for result to wait for scan results before delivering the email, or Submit only to submit emails to FortiSandbox and still deliver the email without waiting for the scan results.
  7. Enable Attachment analysis to send email attachments to the FortiSandbox unit.
  8. Enable URI analysis to send the URIs to the FortiSandbox unit.
  9. Under Attachment analysis and URI analysis specify the action to take if the FortiSandbox analysis determines that an email has a virus or other threat attributes. You can specify different actions according to threat level. Each threat level action is set by default to use the Default action of the antivirus profile.
  10. Click Create.

Creating an AntiVirus profile

  1. Go to Profile > AntiVirus > AntiVirus and click New.
  2. Assign a specific Domain if necessary, otherwise leave it as a System based profile.
  3. Enter a Profile name.
  4. Set Default action to an antivirus action profile. For this example, set to SystemQuarantine.
  5. Note that, in this case, if you set Default action to Reject, the actual action taken will be to fallback to system quarantine, since email messages are to be sent to the FortiSandbox unit.

  6. Under FortiSandbox, set the default Scan mode: Submit and wait for result to wait for scan results before delivering the email, or Submit only to submit emails to FortiSandbox and still deliver the email without waiting for the scan results.
  7. Enable Attachment analysis to send email attachments to the FortiSandbox unit.
  8. Enable URI analysis to send the URIs to the FortiSandbox unit.
  9. Under Attachment analysis and URI analysis specify the action to take if the FortiSandbox analysis determines that an email has a virus or other threat attributes. You can specify different actions according to threat level. Each threat level action is set by default to use the Default action of the antivirus profile.
  10. Click Create.