Fortinet white logo
Fortinet white logo

sandboxing-prefilter

sandboxing-prefilter

Allow user to turn on or off FortiGuard prefiltering of certain file types.

If a file type is associated with a guest VM image, it will be scanned if the file type enters the job queue as defined in the Scan Profile page. The user can turn on FortiGuard prefiltering of a file type so that files of that type will first be statically scanned by an advanced analytic engine, and only suspicious files will be sandboxing scanned by the guest image. This can improve the system's scan performance, and all files will still go through an AV scan, a static scan, and community cloud query steps.

For the URL type, when FortiGuard prefiltering is enabled, only URLs whose web filtering rating is Unrated will be scanned inside associated guest VM image.

Syntax

sandboxing-prefilter [-h|-l|-e|-d] -t[dll|pdf|swf|js|htm|url|office|trustvendor|trustdomain]

Option

Description

-h

Help information.

-e

Enable sandboxing prefilter.

-d

Disable sandboxing prefilter.

-l

Display the status of sandboxing prefilter.

-t

Enable/disable sandboxing prefilter for specific file types: archive, dll, pdf, swf, js, htm, url, office, trustvendor, trustdomain.

archive and trustdomain are enabled by default. Other prefilters are disabled by default.

When trustvendor is selected, executable files from a small internal list of trusted vendors will skip the sandboxing scan step.

When trustdomain is selected, files downloaded from a small internal list of trusted domains will skip the sandboxing scan step

sandboxing-prefilter

sandboxing-prefilter

Allow user to turn on or off FortiGuard prefiltering of certain file types.

If a file type is associated with a guest VM image, it will be scanned if the file type enters the job queue as defined in the Scan Profile page. The user can turn on FortiGuard prefiltering of a file type so that files of that type will first be statically scanned by an advanced analytic engine, and only suspicious files will be sandboxing scanned by the guest image. This can improve the system's scan performance, and all files will still go through an AV scan, a static scan, and community cloud query steps.

For the URL type, when FortiGuard prefiltering is enabled, only URLs whose web filtering rating is Unrated will be scanned inside associated guest VM image.

Syntax

sandboxing-prefilter [-h|-l|-e|-d] -t[dll|pdf|swf|js|htm|url|office|trustvendor|trustdomain]

Option

Description

-h

Help information.

-e

Enable sandboxing prefilter.

-d

Disable sandboxing prefilter.

-l

Display the status of sandboxing prefilter.

-t

Enable/disable sandboxing prefilter for specific file types: archive, dll, pdf, swf, js, htm, url, office, trustvendor, trustdomain.

archive and trustdomain are enabled by default. Other prefilters are disabled by default.

When trustvendor is selected, executable files from a small internal list of trusted vendors will skip the sandboxing scan step.

When trustdomain is selected, files downloaded from a small internal list of trusted domains will skip the sandboxing scan step