Blocking oversized files and emails

Antivirus protection

 

 

Blocking oversized files and emails

You can configure the FortiGate unit to buffer 1 to 15 percent of available memory to store oversized files and email. The FortiGate unit then blocks a file or email that exceeds this limit instead of bypassing antivirus scanning and sending the file or email directly to the server or receiver. The FortiGate unit sends a replacement message for an oversized file or email attachment to the HTTP or email proxy client.

Configuring limits for oversized files and email

1Go to Anti-Virus > Config > Config.

2Type the size limit in MB.

3Select Apply.

Exempting fragmented email from blocking

!

1

2

3

A fragmented email is a large email message that has been split into smaller messages that are sent individually and recombined when they are received. By default when antivirus protection is enabled, the FortiGate unit blocks fragmented emails and replaces them with an email block message that is forwarded to the receiver. It is recommend that you disable the fragmenting of email messages in the client email software.

To exempt fragmented emails from automatic antivirus blocking, you can enable Pass Fragmented Email for the email content protocols (IMAP, POP3, and SMTP).

Caution: The FortiGate unit cannot scan fragmented emails for viruses or use file pattern blocking to remove files from these email messages.

Configure the FortiGate unit to pass fragmented emails by doing the following:

Enable Pass Fragmented Emails for IMAP, POP3, and SMTP traffic in a content profile.

Select Anti-Virus & Web filter in a firewall policy. For example, to pass fragmented emails that internal users send to the external network, select an internal to external policy.

Select a content profile that has Pass Fragmented Emails enabled for the traffic that you want the FortiGate unit to scan.

Viewing the virus list

Use the following procedure to view the names of the viruses and worms in the current virus definition list:

1To display the virus list, go to Anti-Virus > Config > Virus List.

2Scroll through the virus and worm list to view the names of all viruses and worms in the list.

266

Fortinet Inc.

Page 266
Image 266
Fortinet 400 Blocking oversized files and emails, Exempting fragmented email from blocking, Viewing the virus list, 266