Fortinet white logo
Fortinet white logo

Administration Guide

Configuring antivirus profiles

Configuring antivirus profiles

Go to Profile > AntiVirus > AntiVirus to create antivirus profiles that you can select in a policy in order to scan email for viruses.

The FortiMail unit scans email header, body, and attachments (including compressed files, such as ZIP, PKZIP, LHA, ARJ, and RAR files) for virus infections. If the FortiMail unit detects a virus, it will take actions as you define in the antivirus action profiles. For details, see Configuring antivirus action profiles.

FortiMail keeps its antivirus scan engine and virus signature database up-to-date by connecting to Fortinet FortiGuard Distribution Network (FDN) antivirus services.

To configure an antivirus profile

  1. Go to Profile > AntiVirus > AntiVirus.

  2. Either click New to add a profile or double-click a profile to modify it.

  3. Configure the following:

    GUI item

    Description

    Domain

    Select which protected domain this profile belongs to, or System (all protected domains can use this profile).

    You can only see the domains that are permitted by your administrator profile. See About administrator account permissions and domains.

    Name

    Enter a unique name for the profile.

    Comment

    Enter a comment or description.

    Default action

    Select the action profile to apply when the profile detects a virus.

    For each scan in the profile, you can use its Action setting to override this default and select a more specific behavior.

    See also Configuring antivirus action profiles.

  4. Click the arrows to expand each section and configure the following:

    GUI item

    Description

    AntiVirus

    Enable to perform antivirus scanning.

    Malware/virus Outbreak

    Instead of using virus signatures, malware outbreak protection uses data analytic from the FortiGuard Service. For example, if a threshold volume of previously unknown attachments are being sent from known malicious sources, they are treated as suspicious viruses.

    This feature can help quickly identify new threats.

    Because the infected email is treated as virus, the virus replacement message will be used, if the replacement action is triggered.

    Heuristic

    Enable to use real-time malware analysis, or heuristic antivirus scan, when performing antivirus scanning.

    File signature check

    Enable to scan for file signatures. For details, see Configuring file signatures.

    Grayware

    Enable to scan for grayware, such as mail bomb detection.

    FortiNDR

    Enable this option to send potentially harmful attachments, such as executables, PDF, and OCX files, to FortiNDR for further malware analysis. For details about FortiNDR configuration, see Using FortiNDR malware inspection.

    Malicious/Virus

    High risk

    Medium risk

    Low risk

    Specify the action to take if the FortiNDR analysis determines that the email messages have malware or other threat qualities. You can specify different actions according to the threat levels.

    FortiSandbox

    Enable this option to send potentially harmful attachments, such as executables, PDF, and OCX files, to FortiSandbox for further analysis. For details about FortiSandbox configuration, see Using FortiSandbox antivirus inspection.

    Scan mode

    Submit and wait for result means to wait for scan results before delivering the email.

    Submit only means to submit the email to FortiSandbox but still deliver the mail without waiting for scan results.

    Attachment analysis

    Enable to send email attachments to FortiSandbox.

    If desired, configure different actions for different scan results.

    Malicious/Virus

    High risk

    Medium risk

    Low risk

    No Result

    Specify the action to take if the FortiSandbox analysis determines that the email messages have virus or other threat qualities. You can specify different actions according to the threat levels.

    URL analysis

    Enable to send the URLs to FortiSandbox.

    If desired, configure different actions for different scan results.

    Email selection

    Specify to scan URLs in all email or the suspicious email only.

    Malicious/Virus

    High risk

    Medium risk

    Low risk

    No Result

    Specify the action to take if the FortiSandbox analysis determines that the email messages have virus or other threat qualities. You can specify different actions according to the threat levels.

Configuring antivirus profiles

Configuring antivirus profiles

Go to Profile > AntiVirus > AntiVirus to create antivirus profiles that you can select in a policy in order to scan email for viruses.

The FortiMail unit scans email header, body, and attachments (including compressed files, such as ZIP, PKZIP, LHA, ARJ, and RAR files) for virus infections. If the FortiMail unit detects a virus, it will take actions as you define in the antivirus action profiles. For details, see Configuring antivirus action profiles.

FortiMail keeps its antivirus scan engine and virus signature database up-to-date by connecting to Fortinet FortiGuard Distribution Network (FDN) antivirus services.

To configure an antivirus profile

  1. Go to Profile > AntiVirus > AntiVirus.

  2. Either click New to add a profile or double-click a profile to modify it.

  3. Configure the following:

    GUI item

    Description

    Domain

    Select which protected domain this profile belongs to, or System (all protected domains can use this profile).

    You can only see the domains that are permitted by your administrator profile. See About administrator account permissions and domains.

    Name

    Enter a unique name for the profile.

    Comment

    Enter a comment or description.

    Default action

    Select the action profile to apply when the profile detects a virus.

    For each scan in the profile, you can use its Action setting to override this default and select a more specific behavior.

    See also Configuring antivirus action profiles.

  4. Click the arrows to expand each section and configure the following:

    GUI item

    Description

    AntiVirus

    Enable to perform antivirus scanning.

    Malware/virus Outbreak

    Instead of using virus signatures, malware outbreak protection uses data analytic from the FortiGuard Service. For example, if a threshold volume of previously unknown attachments are being sent from known malicious sources, they are treated as suspicious viruses.

    This feature can help quickly identify new threats.

    Because the infected email is treated as virus, the virus replacement message will be used, if the replacement action is triggered.

    Heuristic

    Enable to use real-time malware analysis, or heuristic antivirus scan, when performing antivirus scanning.

    File signature check

    Enable to scan for file signatures. For details, see Configuring file signatures.

    Grayware

    Enable to scan for grayware, such as mail bomb detection.

    FortiNDR

    Enable this option to send potentially harmful attachments, such as executables, PDF, and OCX files, to FortiNDR for further malware analysis. For details about FortiNDR configuration, see Using FortiNDR malware inspection.

    Malicious/Virus

    High risk

    Medium risk

    Low risk

    Specify the action to take if the FortiNDR analysis determines that the email messages have malware or other threat qualities. You can specify different actions according to the threat levels.

    FortiSandbox

    Enable this option to send potentially harmful attachments, such as executables, PDF, and OCX files, to FortiSandbox for further analysis. For details about FortiSandbox configuration, see Using FortiSandbox antivirus inspection.

    Scan mode

    Submit and wait for result means to wait for scan results before delivering the email.

    Submit only means to submit the email to FortiSandbox but still deliver the mail without waiting for scan results.

    Attachment analysis

    Enable to send email attachments to FortiSandbox.

    If desired, configure different actions for different scan results.

    Malicious/Virus

    High risk

    Medium risk

    Low risk

    No Result

    Specify the action to take if the FortiSandbox analysis determines that the email messages have virus or other threat qualities. You can specify different actions according to the threat levels.

    URL analysis

    Enable to send the URLs to FortiSandbox.

    If desired, configure different actions for different scan results.

    Email selection

    Specify to scan URLs in all email or the suspicious email only.

    Malicious/Virus

    High risk

    Medium risk

    Low risk

    No Result

    Specify the action to take if the FortiSandbox analysis determines that the email messages have virus or other threat qualities. You can specify different actions according to the threat levels.