Antivirus Flashcards
What inspection modes can FortiGate operate in?
- Flow-based
- Proxy-based
What is the default inspection mode?
Flow-based
What is required to use antivirus on your FortiGate?
An appropriate license
How does flow-based inspection mode work?
- FortiGate examines the file as it passes through FortiGate
- User sees a faster response than if proxy-based inspection mode was used
How would you enable an Antivirus profile?
In the firewall policy, under Security Profiles, toggle the antivirus
How does proxy-based inspection mode work?
- FortiGate buffers the traffic and examines it as a whole before determining an action
- Allows for more points of data than flow-based inspection
What additional antivirus support does proxy inspection mode offer?
- MAP and SSH protocol inspection
- Content disarm and reconstruction (CDR)
- FortiNDR inspection
From the user’s end, what happens when a virus is detected?
Antivirus block page is displayed
What inspection mode would you use if security was your top priority?
Proxy-based inspection mode
What is required to configure protocol port mapping?
Proxy-based inspection
What additional granularity is provided by using protocol options?
Large files are automatically blocked (threshold can be customized)
What are some fixes for common antivirus issues?
- Verify antivirus license, check for updates
- Correct firewall policy configuration
What type of inspection mode can be offloaded using CP processors?
Flow-based