Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
KPS
New Contributor III

Does every Fortigate-User profit on Fortisandbox-AV-pattern?

Hi!

 

The current Fortigates offer the feature "Use FortiSandbox Database" in AV-profiles.

 

Is there any difference on that feature depending on:

- Using FortiSandbox Cloud

- Using FortiSandbox On-Prem

- Non of both?

 

 

--> Are the pattern, that are detected on any "sharing" Fortisandbox directly pushed to the Fortiguard-Updates, are there differences according to the rest of the FortiSandbox-usage?

 

Thank you for your help!

 

KPS

1 Solution
mworlund_FTNT

If you're referring to the database of samples collected from Fortisandboxes around the world then no, it is the same Fortiguard database referenced in the cloud query engine in FortiSandbox.

View solution in original post

3 REPLIES 3
mworlund_FTNT

If you're referring to the database of samples collected from Fortisandboxes around the world then no, it is the same Fortiguard database referenced in the cloud query engine in FortiSandbox.

ede_pfau

There are differences, of course.

(disclaimer: as far as I have understood...)

 

1- FSA Cloud

Positive results are added to the regular, worldwide FortiGuard AV database, and thus eventually distributed to your FGT. To minimize delay, enable "push updates".

 

2- FSA on premise

Positive results lead to the creation of an AV signature update which is offered immediately on your local network. Devices have to subscribe to these updates. Optionally, the updates are added to the regular, worldwide FortiGuard AV database.

 

Fortigates in your network may actively submit files to the local FSA, or just participate in the FSA updates. This way, only the main firewalls and FortiMail submit files (to conserve FSA resources) but all Fortinet devices profit from the findings.

 

3- neither FSA Cloud subscription nor on premise

You get the regular FortiGuard AV updates, i.e., the switch is not effective.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
emnoc
Esteemed Contributor III

I think for virus outbreak fortiguard has to validate the sample submitted b4 they are provided as a globally supplied signature.

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors