Fortinet white logo
Fortinet white logo

CLI Reference

config antivirus profile

config antivirus profile

Configure AntiVirus profiles.

config antivirus profile
    Description: Configure AntiVirus profiles.
    edit <name>
        set comment {var-string}
        set replacemsg-group {string}
        set ftgd-analytics [disable|suspicious|...]
        set analytics-max-upload {integer}
        set analytics-wl-filetype {integer}
        set analytics-bl-filetype {integer}
        set analytics-db [disable|enable]
        set mobile-malware-db [disable|enable]
        config http
            Description: Configure HTTP AntiVirus options.
            set options [scan|avmonitor|...]
            set archive-block [encrypted|corrupted|...]
            set archive-log [encrypted|corrupted|...]
            set emulator [enable|disable]
        end
        config ftp
            Description: Configure FTP AntiVirus options.
            set options [scan|avmonitor|...]
            set archive-block [encrypted|corrupted|...]
            set archive-log [encrypted|corrupted|...]
            set emulator [enable|disable]
        end
        config imap
            Description: Configure IMAP AntiVirus options.
            set options [scan|avmonitor|...]
            set archive-block [encrypted|corrupted|...]
            set archive-log [encrypted|corrupted|...]
            set emulator [enable|disable]
            set executables [default|virus]
        end
        config pop3
            Description: Configure POP3 AntiVirus options.
            set options [scan|avmonitor|...]
            set archive-block [encrypted|corrupted|...]
            set archive-log [encrypted|corrupted|...]
            set emulator [enable|disable]
            set executables [default|virus]
        end
        config smtp
            Description: Configure SMTP AntiVirus options.
            set options [scan|avmonitor|...]
            set archive-block [encrypted|corrupted|...]
            set archive-log [encrypted|corrupted|...]
            set emulator [enable|disable]
            set executables [default|virus]
        end
        config mapi
            Description: Configure MAPI AntiVirus options.
            set options [scan|avmonitor|...]
            set archive-block [encrypted|corrupted|...]
            set archive-log [encrypted|corrupted|...]
            set emulator [enable|disable]
            set executables [default|virus]
        end
        config cifs
            Description: Configure CIFS AntiVirus options.
            set options [scan|avmonitor|...]
            set archive-block [encrypted|corrupted|...]
            set archive-log [encrypted|corrupted|...]
            set emulator [enable|disable]
        end
        config ssh
            Description: Configure SFTP and SCP AntiVirus options.
            set options [scan|avmonitor|...]
            set archive-block [encrypted|corrupted|...]
            set archive-log [encrypted|corrupted|...]
            set emulator [enable|disable]
        end
        config nac-quar
            Description: Configure AntiVirus quarantine settings.
            set infected [none|quar-src-ip]
            set expiry {user}
            set log [enable|disable]
        end
        set av-virus-log [enable|disable]
        set av-block-log [enable|disable]
        set scan-mode [default|legacy]
    next
end

config antivirus profile

Parameter

Description

Type

Size

name

Profile name.

string

Maximum length: 35

comment

Comment.

var-string

Maximum length: 255

replacemsg-group

Replacement message group customized for this profile.

string

Maximum length: 35

ftgd-analytics

Settings to control which files are uploaded to FortiSandbox.

option

-

Option

Description

disable

Do not upload files to FortiSandbox.

suspicious

Submit files supported by FortiSandbox if heuristics or other methods determine they are suspicious.

everything

Submit all files scanned by AntiVirus to FortiSandbox. AntiVirus may not scan all files.

analytics-max-upload

Maximum size of files that can be uploaded to FortiSandbox.

integer

Minimum value: 1 Maximum value: 435

analytics-wl-filetype

Do not submit files matching this DLP file-pattern to FortiSandbox.

integer

Minimum value: 0 Maximum value: 4294967295

analytics-bl-filetype

Only submit files matching this DLP file-pattern to FortiSandbox.

integer

Minimum value: 0 Maximum value: 4294967295

analytics-db

Enable/disable using the FortiSandbox signature database to supplement the AV signature databases.

option

-

Option

Description

disable

Use only the standard AV signature databases.

enable

Also use the FortiSandbox signature database.

mobile-malware-db

Enable/disable using the mobile malware signature database.

option

-

Option

Description

disable

Do not use the mobile malware signature database.

enable

Also use the mobile malware signature database.

av-virus-log

Enable/disable AntiVirus logging.

option

-

Option

Description

enable

Enable AntiVirus logging.

disable

Disable AntiVirus logging.

av-block-log

Enable/disable logging for AntiVirus file blocking.

option

-

Option

Description

enable

Enable logging for AntiVirus file blocking.

disable

Disable logging for AntiVirus file blocking.

scan-mode

Choose between default scan mode and legacy scan mode.

option

-

Option

Description

default

Aggregate scanning mode.

legacy

Force scanunit to scan all files.

config http

Parameter

Description

Type

Size

options

Enable/disable HTTP AntiVirus scanning, monitoring, and quarantine.

option

-

Option

Description

scan

Enable HTTP antivirus scanning.

avmonitor

Enable HTTP antivirus logging.

quarantine

Enable HTTP antivirus quarantine. Files are quarantined depending on quarantine settings.

archive-block

Select the archive types to block.

option

-

Option

Description

encrypted

Block encrypted archives.

corrupted

Block corrupted archives.

multipart

Block multipart archives.

nested

Block nested archives.

mailbomb

Block mail bomb archives.

unhandled

Block archives that FortiProxy cannot open.

archive-log

Select the archive types to log.

option

-

Option

Description

encrypted

Log encrypted archives.

corrupted

Log corrupted archives.

multipart

Log multipart archives.

nested

Log nested archives.

mailbomb

Log mail bomb archives.

unhandled

Log archives that FortiProxy cannot open.

emulator

Enable/disable the virus emulator.

option

-

Option

Description

enable

Enable the virus emulator.

disable

Disable the virus emulator.

config ftp

Parameter

Description

Type

Size

options

Enable/disable FTP AntiVirus scanning, monitoring, and quarantine.

option

-

Option

Description

scan

Enable FTP antivirus scanning.

avmonitor

Enable FTP antivirus logging.

quarantine

Enable FTP antivirus quarantine. Files are quarantined depending on quarantine settings.

archive-block

Select the archive types to block.

option

-

Option

Description

encrypted

Block encrypted archives.

corrupted

Block corrupted archives.

multipart

Block multipart archives.

nested

Block nested archives.

mailbomb

Block mail bomb archives.

unhandled

Block archives that FortiProxy cannot open.

archive-log

Select the archive types to log.

option

-

Option

Description

encrypted

Log encrypted archives.

corrupted

Log corrupted archives.

multipart

Log multipart archives.

nested

Log nested archives.

mailbomb

Log mail bomb archives.

unhandled

Log archives that FortiProxy cannot open.

emulator

Enable/disable the virus emulator.

option

-

Option

Description

enable

Enable the virus emulator.

disable

Disable the virus emulator.

config imap

Parameter

Description

Type

Size

options

Enable/disable IMAP AntiVirus scanning, monitoring, and quarantine.

option

-

Option

Description

scan

Enable IMAP antivirus scanning.

avmonitor

Enable IMAP antivirus logging.

quarantine

Enable IMAP antivirus quarantine. Files are quarantined depending on quarantine settings.

archive-block

Select the archive types to block.

option

-

Option

Description

encrypted

Block encrypted archives.

corrupted

Block corrupted archives.

multipart

Block multipart archives.

nested

Block nested archives.

mailbomb

Block mail bomb archives.

unhandled

Block archives that FortiProxy cannot open.

archive-log

Select the archive types to log.

option

-

Option

Description

encrypted

Log encrypted archives.

corrupted

Log corrupted archives.

multipart

Log multipart archives.

nested

Log nested archives.

mailbomb

Log mail bomb archives.

unhandled

Log archives that FortiProxy cannot open.

emulator

Enable/disable the virus emulator.

option

-

Option

Description

enable

Enable the virus emulator.

disable

Disable the virus emulator.

executables

Treat Windows executable files as viruses for the purpose of blocking or monitoring.

option

-

Option

Description

default

Perform standard AntiVirus scanning of Windows executable files.

virus

Treat Windows executables as viruses.

config pop3

Parameter

Description

Type

Size

options

Enable/disable POP3 AntiVirus scanning, monitoring, and quarantine.

option

-

Option

Description

scan

Enable POP3 antivirus scanning.

avmonitor

Enable POP3 antivirus logging.

quarantine

Enable POP3 antivirus quarantine. Files are quarantined depending on quarantine settings.

archive-block

Select the archive types to block.

option

-

Option

Description

encrypted

Block encrypted archives.

corrupted

Block corrupted archives.

multipart

Block multipart archives.

nested

Block nested archives.

mailbomb

Block mail bomb archives.

unhandled

Block archives that FortiProxy cannot open.

archive-log

Select the archive types to log.

option

-

Option

Description

encrypted

Log encrypted archives.

corrupted

Log corrupted archives.

multipart

Log multipart archives.

nested

Log nested archives.

mailbomb

Log mail bomb archives.

unhandled

Log archives that FortiProxy cannot open.

emulator

Enable/disable the virus emulator.

option

-

Option

Description

enable

Enable the virus emulator.

disable

Disable the virus emulator.

executables

Treat Windows executable files as viruses for the purpose of blocking or monitoring.

option

-

Option

Description

default

Perform standard AntiVirus scanning of Windows executable files.

virus

Treat Windows executables as viruses.

config smtp

Parameter

Description

Type

Size

options

Enable/disable SMTP AntiVirus scanning, monitoring, and quarantine.

option

-

Option

Description

scan

Enable SMTP antivirus scanning.

avmonitor

Enable SMTP antivirus logging.

quarantine

Enable SMTP antivirus quarantine. Files are quarantined depending on quarantine settings.

archive-block

Select the archive types to block.

option

-

Option

Description

encrypted

Block encrypted archives.

corrupted

Block corrupted archives.

multipart

Block multipart archives.

nested

Block nested archives.

mailbomb

Block mail bomb archives.

unhandled

Block archives that FortiProxy cannot open.

archive-log

Select the archive types to log.

option

-

Option

Description

encrypted

Log encrypted archives.

corrupted

Log corrupted archives.

multipart

Log multipart archives.

nested

Log nested archives.

mailbomb

Log mail bomb archives.

unhandled

Log archives that FortiProxy cannot open.

emulator

Enable/disable the virus emulator.

option

-

Option

Description

enable

Enable the virus emulator.

disable

Disable the virus emulator.

executables

Treat Windows executable files as viruses for the purpose of blocking or monitoring.

option

-

Option

Description

default

Perform standard AntiVirus scanning of Windows executable files.

virus

Treat Windows executables as viruses.

config mapi

Parameter

Description

Type

Size

options

Enable/disable MAPI AntiVirus scanning, monitoring, and quarantine.

option

-

Option

Description

scan

Enable MAPI antivirus scanning.

avmonitor

Enable MAPI antivirus logging.

quarantine

Enable MAPI antivirus quarantine. Files are quarantined depending on quarantine settings.

archive-block

Select the archive types to block.

option

-

Option

Description

encrypted

Block encrypted archives.

corrupted

Block corrupted archives.

multipart

Block multipart archives.

nested

Block nested archives.

mailbomb

Block mail bomb archives.

unhandled

Block archives that FortiProxy cannot open.

archive-log

Select the archive types to log.

option

-

Option

Description

encrypted

Log encrypted archives.

corrupted

Log corrupted archives.

multipart

Log multipart archives.

nested

Log nested archives.

mailbomb

Log mail bomb archives.

unhandled

Log archives that FortiProxy cannot open.

emulator

Enable/disable the virus emulator.

option

-

Option

Description

enable

Enable the virus emulator.

disable

Disable the virus emulator.

executables

Treat Windows executable files as viruses for the purpose of blocking or monitoring.

option

-

Option

Description

default

Perform standard AntiVirus scanning of Windows executable files.

virus

Treat Windows executables as viruses.

config cifs

Parameter

Description

Type

Size

options

Enable/disable CIFS AntiVirus scanning, monitoring, and quarantine.

option

-

Option

Description

scan

Enable CIFS antivirus scanning.

avmonitor

Enable CIFS antivirus logging.

quarantine

Enable CIFS antivirus quarantine. Files are quarantined depending on quarantine settings.

archive-block

Select the archive types to block.

option

-

Option

Description

encrypted

Block encrypted archives.

corrupted

Block corrupted archives.

multipart

Block multipart archives.

nested

Block nested archives.

mailbomb

Block mail bomb archives.

unhandled

Block archives that FortiProxy cannot open.

archive-log

Select the archive types to log.

option

-

Option

Description

encrypted

Log encrypted archives.

corrupted

Log corrupted archives.

multipart

Log multipart archives.

nested

Log nested archives.

mailbomb

Log mail bomb archives.

unhandled

Log archives that FortiProxy cannot open.

emulator

Enable/disable the virus emulator.

option

-

Option

Description

enable

Enable the virus emulator.

disable

Disable the virus emulator.

config ssh

Parameter

Description

Type

Size

options

Enable/disable SFTP and SCP AntiVirus scanning, monitoring, and quarantine.

option

-

Option

Description

scan

Enable SSH antivirus scanning.

avmonitor

Enable SSH antivirus logging.

quarantine

Enable SSH antivirus quarantine. Files are quarantined depending on quarantine settings.

archive-block

Select the archive types to block.

option

-

Option

Description

encrypted

Block encrypted archives.

corrupted

Block corrupted archives.

multipart

Block multipart archives.

nested

Block nested archives.

mailbomb

Block mail bomb archives.

unhandled

Block archives that FortiProxy cannot open.

archive-log

Select the archive types to log.

option

-

Option

Description

encrypted

Log encrypted archives.

corrupted

Log corrupted archives.

multipart

Log multipart archives.

nested

Log nested archives.

mailbomb

Log mail bomb archives.

unhandled

Log archives that FortiProxy cannot open.

emulator

Enable/disable the virus emulator.

option

-

Option

Description

enable

Enable the virus emulator.

disable

Disable the virus emulator.

config nac-quar

Parameter

Description

Type

Size

infected

Enable/Disable quarantining infected hosts to the banned user list.

option

-

Option

Description

none

Do not quarantine infected hosts.

quar-src-ip

Quarantine all traffic from the infected hosts source IP.

expiry

Duration of quarantine.

user

Not Specified

log

Enable/disable AntiVirus quarantine logging.

option

-

Option

Description

enable

Enable AntiVirus quarantine logging.

disable

Disable AntiVirus quarantine logging.

config antivirus profile

config antivirus profile

Configure AntiVirus profiles.

config antivirus profile
    Description: Configure AntiVirus profiles.
    edit <name>
        set comment {var-string}
        set replacemsg-group {string}
        set ftgd-analytics [disable|suspicious|...]
        set analytics-max-upload {integer}
        set analytics-wl-filetype {integer}
        set analytics-bl-filetype {integer}
        set analytics-db [disable|enable]
        set mobile-malware-db [disable|enable]
        config http
            Description: Configure HTTP AntiVirus options.
            set options [scan|avmonitor|...]
            set archive-block [encrypted|corrupted|...]
            set archive-log [encrypted|corrupted|...]
            set emulator [enable|disable]
        end
        config ftp
            Description: Configure FTP AntiVirus options.
            set options [scan|avmonitor|...]
            set archive-block [encrypted|corrupted|...]
            set archive-log [encrypted|corrupted|...]
            set emulator [enable|disable]
        end
        config imap
            Description: Configure IMAP AntiVirus options.
            set options [scan|avmonitor|...]
            set archive-block [encrypted|corrupted|...]
            set archive-log [encrypted|corrupted|...]
            set emulator [enable|disable]
            set executables [default|virus]
        end
        config pop3
            Description: Configure POP3 AntiVirus options.
            set options [scan|avmonitor|...]
            set archive-block [encrypted|corrupted|...]
            set archive-log [encrypted|corrupted|...]
            set emulator [enable|disable]
            set executables [default|virus]
        end
        config smtp
            Description: Configure SMTP AntiVirus options.
            set options [scan|avmonitor|...]
            set archive-block [encrypted|corrupted|...]
            set archive-log [encrypted|corrupted|...]
            set emulator [enable|disable]
            set executables [default|virus]
        end
        config mapi
            Description: Configure MAPI AntiVirus options.
            set options [scan|avmonitor|...]
            set archive-block [encrypted|corrupted|...]
            set archive-log [encrypted|corrupted|...]
            set emulator [enable|disable]
            set executables [default|virus]
        end
        config cifs
            Description: Configure CIFS AntiVirus options.
            set options [scan|avmonitor|...]
            set archive-block [encrypted|corrupted|...]
            set archive-log [encrypted|corrupted|...]
            set emulator [enable|disable]
        end
        config ssh
            Description: Configure SFTP and SCP AntiVirus options.
            set options [scan|avmonitor|...]
            set archive-block [encrypted|corrupted|...]
            set archive-log [encrypted|corrupted|...]
            set emulator [enable|disable]
        end
        config nac-quar
            Description: Configure AntiVirus quarantine settings.
            set infected [none|quar-src-ip]
            set expiry {user}
            set log [enable|disable]
        end
        set av-virus-log [enable|disable]
        set av-block-log [enable|disable]
        set scan-mode [default|legacy]
    next
end

config antivirus profile

Parameter

Description

Type

Size

name

Profile name.

string

Maximum length: 35

comment

Comment.

var-string

Maximum length: 255

replacemsg-group

Replacement message group customized for this profile.

string

Maximum length: 35

ftgd-analytics

Settings to control which files are uploaded to FortiSandbox.

option

-

Option

Description

disable

Do not upload files to FortiSandbox.

suspicious

Submit files supported by FortiSandbox if heuristics or other methods determine they are suspicious.

everything

Submit all files scanned by AntiVirus to FortiSandbox. AntiVirus may not scan all files.

analytics-max-upload

Maximum size of files that can be uploaded to FortiSandbox.

integer

Minimum value: 1 Maximum value: 435

analytics-wl-filetype

Do not submit files matching this DLP file-pattern to FortiSandbox.

integer

Minimum value: 0 Maximum value: 4294967295

analytics-bl-filetype

Only submit files matching this DLP file-pattern to FortiSandbox.

integer

Minimum value: 0 Maximum value: 4294967295

analytics-db

Enable/disable using the FortiSandbox signature database to supplement the AV signature databases.

option

-

Option

Description

disable

Use only the standard AV signature databases.

enable

Also use the FortiSandbox signature database.

mobile-malware-db

Enable/disable using the mobile malware signature database.

option

-

Option

Description

disable

Do not use the mobile malware signature database.

enable

Also use the mobile malware signature database.

av-virus-log

Enable/disable AntiVirus logging.

option

-

Option

Description

enable

Enable AntiVirus logging.

disable

Disable AntiVirus logging.

av-block-log

Enable/disable logging for AntiVirus file blocking.

option

-

Option

Description

enable

Enable logging for AntiVirus file blocking.

disable

Disable logging for AntiVirus file blocking.

scan-mode

Choose between default scan mode and legacy scan mode.

option

-

Option

Description

default

Aggregate scanning mode.

legacy

Force scanunit to scan all files.

config http

Parameter

Description

Type

Size

options

Enable/disable HTTP AntiVirus scanning, monitoring, and quarantine.

option

-

Option

Description

scan

Enable HTTP antivirus scanning.

avmonitor

Enable HTTP antivirus logging.

quarantine

Enable HTTP antivirus quarantine. Files are quarantined depending on quarantine settings.

archive-block

Select the archive types to block.

option

-

Option

Description

encrypted

Block encrypted archives.

corrupted

Block corrupted archives.

multipart

Block multipart archives.

nested

Block nested archives.

mailbomb

Block mail bomb archives.

unhandled

Block archives that FortiProxy cannot open.

archive-log

Select the archive types to log.

option

-

Option

Description

encrypted

Log encrypted archives.

corrupted

Log corrupted archives.

multipart

Log multipart archives.

nested

Log nested archives.

mailbomb

Log mail bomb archives.

unhandled

Log archives that FortiProxy cannot open.

emulator

Enable/disable the virus emulator.

option

-

Option

Description

enable

Enable the virus emulator.

disable

Disable the virus emulator.

config ftp

Parameter

Description

Type

Size

options

Enable/disable FTP AntiVirus scanning, monitoring, and quarantine.

option

-

Option

Description

scan

Enable FTP antivirus scanning.

avmonitor

Enable FTP antivirus logging.

quarantine

Enable FTP antivirus quarantine. Files are quarantined depending on quarantine settings.

archive-block

Select the archive types to block.

option

-

Option

Description

encrypted

Block encrypted archives.

corrupted

Block corrupted archives.

multipart

Block multipart archives.

nested

Block nested archives.

mailbomb

Block mail bomb archives.

unhandled

Block archives that FortiProxy cannot open.

archive-log

Select the archive types to log.

option

-

Option

Description

encrypted

Log encrypted archives.

corrupted

Log corrupted archives.

multipart

Log multipart archives.

nested

Log nested archives.

mailbomb

Log mail bomb archives.

unhandled

Log archives that FortiProxy cannot open.

emulator

Enable/disable the virus emulator.

option

-

Option

Description

enable

Enable the virus emulator.

disable

Disable the virus emulator.

config imap

Parameter

Description

Type

Size

options

Enable/disable IMAP AntiVirus scanning, monitoring, and quarantine.

option

-

Option

Description

scan

Enable IMAP antivirus scanning.

avmonitor

Enable IMAP antivirus logging.

quarantine

Enable IMAP antivirus quarantine. Files are quarantined depending on quarantine settings.

archive-block

Select the archive types to block.

option

-

Option

Description

encrypted

Block encrypted archives.

corrupted

Block corrupted archives.

multipart

Block multipart archives.

nested

Block nested archives.

mailbomb

Block mail bomb archives.

unhandled

Block archives that FortiProxy cannot open.

archive-log

Select the archive types to log.

option

-

Option

Description

encrypted

Log encrypted archives.

corrupted

Log corrupted archives.

multipart

Log multipart archives.

nested

Log nested archives.

mailbomb

Log mail bomb archives.

unhandled

Log archives that FortiProxy cannot open.

emulator

Enable/disable the virus emulator.

option

-

Option

Description

enable

Enable the virus emulator.

disable

Disable the virus emulator.

executables

Treat Windows executable files as viruses for the purpose of blocking or monitoring.

option

-

Option

Description

default

Perform standard AntiVirus scanning of Windows executable files.

virus

Treat Windows executables as viruses.

config pop3

Parameter

Description

Type

Size

options

Enable/disable POP3 AntiVirus scanning, monitoring, and quarantine.

option

-

Option

Description

scan

Enable POP3 antivirus scanning.

avmonitor

Enable POP3 antivirus logging.

quarantine

Enable POP3 antivirus quarantine. Files are quarantined depending on quarantine settings.

archive-block

Select the archive types to block.

option

-

Option

Description

encrypted

Block encrypted archives.

corrupted

Block corrupted archives.

multipart

Block multipart archives.

nested

Block nested archives.

mailbomb

Block mail bomb archives.

unhandled

Block archives that FortiProxy cannot open.

archive-log

Select the archive types to log.

option

-

Option

Description

encrypted

Log encrypted archives.

corrupted

Log corrupted archives.

multipart

Log multipart archives.

nested

Log nested archives.

mailbomb

Log mail bomb archives.

unhandled

Log archives that FortiProxy cannot open.

emulator

Enable/disable the virus emulator.

option

-

Option

Description

enable

Enable the virus emulator.

disable

Disable the virus emulator.

executables

Treat Windows executable files as viruses for the purpose of blocking or monitoring.

option

-

Option

Description

default

Perform standard AntiVirus scanning of Windows executable files.

virus

Treat Windows executables as viruses.

config smtp

Parameter

Description

Type

Size

options

Enable/disable SMTP AntiVirus scanning, monitoring, and quarantine.

option

-

Option

Description

scan

Enable SMTP antivirus scanning.

avmonitor

Enable SMTP antivirus logging.

quarantine

Enable SMTP antivirus quarantine. Files are quarantined depending on quarantine settings.

archive-block

Select the archive types to block.

option

-

Option

Description

encrypted

Block encrypted archives.

corrupted

Block corrupted archives.

multipart

Block multipart archives.

nested

Block nested archives.

mailbomb

Block mail bomb archives.

unhandled

Block archives that FortiProxy cannot open.

archive-log

Select the archive types to log.

option

-

Option

Description

encrypted

Log encrypted archives.

corrupted

Log corrupted archives.

multipart

Log multipart archives.

nested

Log nested archives.

mailbomb

Log mail bomb archives.

unhandled

Log archives that FortiProxy cannot open.

emulator

Enable/disable the virus emulator.

option

-

Option

Description

enable

Enable the virus emulator.

disable

Disable the virus emulator.

executables

Treat Windows executable files as viruses for the purpose of blocking or monitoring.

option

-

Option

Description

default

Perform standard AntiVirus scanning of Windows executable files.

virus

Treat Windows executables as viruses.

config mapi

Parameter

Description

Type

Size

options

Enable/disable MAPI AntiVirus scanning, monitoring, and quarantine.

option

-

Option

Description

scan

Enable MAPI antivirus scanning.

avmonitor

Enable MAPI antivirus logging.

quarantine

Enable MAPI antivirus quarantine. Files are quarantined depending on quarantine settings.

archive-block

Select the archive types to block.

option

-

Option

Description

encrypted

Block encrypted archives.

corrupted

Block corrupted archives.

multipart

Block multipart archives.

nested

Block nested archives.

mailbomb

Block mail bomb archives.

unhandled

Block archives that FortiProxy cannot open.

archive-log

Select the archive types to log.

option

-

Option

Description

encrypted

Log encrypted archives.

corrupted

Log corrupted archives.

multipart

Log multipart archives.

nested

Log nested archives.

mailbomb

Log mail bomb archives.

unhandled

Log archives that FortiProxy cannot open.

emulator

Enable/disable the virus emulator.

option

-

Option

Description

enable

Enable the virus emulator.

disable

Disable the virus emulator.

executables

Treat Windows executable files as viruses for the purpose of blocking or monitoring.

option

-

Option

Description

default

Perform standard AntiVirus scanning of Windows executable files.

virus

Treat Windows executables as viruses.

config cifs

Parameter

Description

Type

Size

options

Enable/disable CIFS AntiVirus scanning, monitoring, and quarantine.

option

-

Option

Description

scan

Enable CIFS antivirus scanning.

avmonitor

Enable CIFS antivirus logging.

quarantine

Enable CIFS antivirus quarantine. Files are quarantined depending on quarantine settings.

archive-block

Select the archive types to block.

option

-

Option

Description

encrypted

Block encrypted archives.

corrupted

Block corrupted archives.

multipart

Block multipart archives.

nested

Block nested archives.

mailbomb

Block mail bomb archives.

unhandled

Block archives that FortiProxy cannot open.

archive-log

Select the archive types to log.

option

-

Option

Description

encrypted

Log encrypted archives.

corrupted

Log corrupted archives.

multipart

Log multipart archives.

nested

Log nested archives.

mailbomb

Log mail bomb archives.

unhandled

Log archives that FortiProxy cannot open.

emulator

Enable/disable the virus emulator.

option

-

Option

Description

enable

Enable the virus emulator.

disable

Disable the virus emulator.

config ssh

Parameter

Description

Type

Size

options

Enable/disable SFTP and SCP AntiVirus scanning, monitoring, and quarantine.

option

-

Option

Description

scan

Enable SSH antivirus scanning.

avmonitor

Enable SSH antivirus logging.

quarantine

Enable SSH antivirus quarantine. Files are quarantined depending on quarantine settings.

archive-block

Select the archive types to block.

option

-

Option

Description

encrypted

Block encrypted archives.

corrupted

Block corrupted archives.

multipart

Block multipart archives.

nested

Block nested archives.

mailbomb

Block mail bomb archives.

unhandled

Block archives that FortiProxy cannot open.

archive-log

Select the archive types to log.

option

-

Option

Description

encrypted

Log encrypted archives.

corrupted

Log corrupted archives.

multipart

Log multipart archives.

nested

Log nested archives.

mailbomb

Log mail bomb archives.

unhandled

Log archives that FortiProxy cannot open.

emulator

Enable/disable the virus emulator.

option

-

Option

Description

enable

Enable the virus emulator.

disable

Disable the virus emulator.

config nac-quar

Parameter

Description

Type

Size

infected

Enable/Disable quarantining infected hosts to the banned user list.

option

-

Option

Description

none

Do not quarantine infected hosts.

quar-src-ip

Quarantine all traffic from the infected hosts source IP.

expiry

Duration of quarantine.

user

Not Specified

log

Enable/disable AntiVirus quarantine logging.

option

-

Option

Description

enable

Enable AntiVirus quarantine logging.

disable

Disable AntiVirus quarantine logging.