Firewall
Protection profile
FortiGate-3000 Administration Guide
01-28006-0010-20041105
239
http
{bannedword block
catblock
chunkedbypass
content_log
oversize
quarantine scan
scriptfilter
urlblock
urlexempt}
Select the actions that this profile will
use for filtering HTTP traffic for a
policy.
Enter
chunkedbypass
to allow web
sites that use chunked encoding for
HTTP to bypass the firewall. Chunked
encoding means the HTTP message
body is altered to allow it to be
transferred in a series of chunks. Use
this feature at your own risk. Malicious
content could enter your network if you
allow web content to bypass the
firewall.
Enter all the actions you want this
profile to use. Use a space to separate
the options you enter. If you want to
remove an option from the list or add
an option to the list, you must retype
the list with the option removed or
added.
No default. All models.
smtp
{bannedword block
content_log
fragmail oversize
quarantine
scan spamemailbwl
spamhdrcheck
spamhelodns
spamipbwl
spamraddrdns
spamrbl
splice
}
Select the actions that this profile will
use for filtering SMTP traffic for a
policy.
Entering
splice
enables the
FortiGate unit to simultaneously scan
an email and send it to the SMTP
server. If the FortiGate unit detects a
virus, it terminates the server
connection and returns an error
message to the sender, listing the virus
name and infected filename. In this
mode, the SMTP server is not able to
deliver the email if it was sent with an
infected attachment. Throughput is
higher when splice is enabled. When
splice is disabled, the FortiGate unit
scans the email first. If the FortiGate
unit detects a virus, it removes the
infected attachment, adds a
customizable message, and sends the
email to the SMTP server for delivery.
Selecting enable for the splice
keyword returns an error message to
the sender if an attachment is infected.
The receiver does not receive the
email or the attachment. When splice
is disabled for SMTP, infected
attachments are removed and the
email is forwarded (without the
attachment) to the SMTP server for
delivery to the recipient.
Enter all the actions you want this
profile to use. Use a space to separate
the options you enter. If you want to
remove an option from the list or add
an option to the list, you must retype
the list with the option removed or
added.
fragmail
All models.
firewall profile command keywords and variables (Continued)
Keywords and
variables
Description
Default
Availability
Summary of Contents for FortiGate 3000
Page 18: ...Contents 18 01 28006 0010 20041105 Fortinet Inc ...
Page 52: ...52 01 28006 0010 20041105 Fortinet Inc Changing the FortiGate firmware System status ...
Page 78: ...78 01 28006 0010 20041105 Fortinet Inc FortiGate IPv6 support System network ...
Page 86: ...86 01 28006 0010 20041105 Fortinet Inc Dynamic IP System DHCP ...
Page 116: ...116 01 28006 0010 20041105 Fortinet Inc FortiManager System config ...
Page 122: ...122 01 28006 0010 20041105 Fortinet Inc Access profiles System administration ...
Page 252: ...252 01 28006 0010 20041105 Fortinet Inc CLI configuration Users and authentication ...
Page 390: ...390 01 28006 0010 20041105 Fortinet Inc Glossary ...
Page 398: ...398 01 28006 0010 20041105 Fortinet Inc Index ...