Test Installation with a file scan
To verify the configuration is successful, perform an on-demand file scan with a Windows VM clone.
To perform an on-demand file scan with a Windows VM clone
-
On the FortiSandbox GUI, go to Scan Policy and Object > VM Settings and change Clone # to 1. Expand the clone number after vminit is completed. Click Apply to trigger the VM initialization.
-
In a new CLI console window, check the VM clone initialization using the command:
diagnose-debug vminit
-
After VM is initialized, the Status of the VM in GUI will be In Use. Go to the Dashboard->Connectivity and Services to verify there is a green checkmark beside Custom VM.
-
To associate file extensions to the custom VM, go to Scan Policy and Object> Scan Profile and click the VM Association tab.
-
Test the installation:
-
Go to Scan Job > File On-Demand > Submit File.
-
Select the file, enable , skip all the static scan, enable and , select the VM just initialized, then click Submit.
-
-
When the scan is finished, click the listed job then click the icon to view job details in File On-Demand page.
-
(Optional) Interaction with a custom VM clone during scan:
-
Go to Scan Job > File On-Demand or URL on-Demand and click Submit File or Submit File/URL.
-
Enable Force to scan and Allow interaction.
-
Select Force to scan inside the following VMs and select the custom VM.
-
Click Submit.
-
Go to Scan Policy and Object> VM Settings and click VM Screenshot.
-
When the icon in the Interaction column is enabled, click the icon to establish an RDP tunnel with the Serial Number as password.
-
Click Yes to manually start the scan process with VM Interaction.
-
When the FortiSandbox tracer engine displays the PDF/Office sample, execute the exe sample or open the URL, etc…, you can click Yes to manually stop the scan process.
-
When the scan is finished, go to the job details page to view the scan results.
-