Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
advlaser
New Contributor

Initial Fortigate Setup and VIP

I just bought a Fortigate 60E and I'm doing the initial setup. When I'm setting up VIP (1to1 nat) for my servers and all I'm opening are 80, 443, 21 does it make sense to check the anti-virus on the ipv4 security policy or is that just a waste of time? Thanks!

1 REPLY 1
ede_pfau
Esteemed Contributor III

HTTP and FTP use cleartext so AV is advisable. If you activate SSL inspection the FGT can even scan HTTPS traffic.

I would not publish a server without scanning for AV and IPS (cross site scripting, SQL injection,...the top 10 vulnerabilities).


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors