Log&Report
Content Archive
FortiGate Version 4.0 Administration Guide
01-400-89802-20090424
669
•
In most cases you would probably not want to content archive email identified as spam so
you can leave these options disabled. However, if you want to content archive email
identified as Spam you can use the following procedure to enabled content archiving of
email identified as spam.
To enable content archiving of email messages identified as spam by the FortiGate
unit or by FortiGuard Antispam
1
Go to
Firewall > Protection Profile
.
2
Create or edit a protection profile.
3
Select the Expand Arrow to view the
Data Leak Prevention Sensor
option.
4
Select the DLP sensor for content archiving from the list.
5
Select the check boxes for the email protocols to content archive spam for beside
Archive SPAMed email to FortiAnalyzer/FortiGuard.
6
Select
OK
.
Configuring VoIP content archiving
You can use the application control CLI commands described in this section to content
archive SIP, SIMPLE and SCCP protocols. You can enable summary content archiving or
the SIP, SIMPLE and SCCP. You can enable full content archiving for SIMPLE.
To save time, you can add application control lists containing the VoIP category options
from the web-based manager before using the CLI to enable content archiving for the
VoIP protocols. For more information about configuring application lists, see
an application control list” on page 525
Then you add the application control lists to protection profiles and add the protection
profiles to firewall policies. The application control list settings then content archive
sessions for the configured VoIP protocols.
For more information about VoIP content archiving commands, see the
. The following procedure assumes that you have already configured an
application control list for VoIP content archiving.
To configure VoIP content archiving
1
Verify that you have the correct application control list for VoIP content archiving.
2
Verify that logging is enabled for that application control VoIP list.
3
Log in to the CLI.
4
Enter the following to access the application control VoIP list and the entries:
config application list
edit <name>
config entries
edit <entry_identification>
5
Enter one of the following to enable content archiving for the entry you chose in step 5:
set sip-archive-summary enable
set sccp-archive-summary enable
set simple-archive-summary enable
6
If you want to enable full content archiving of SIMPLE, enter the following:
Note:
Infected files are clearly indicated in the Content Archive message list so that you
know which content archives are infected and which are not.
Summary of Contents for Gate 60D
Page 705: ...www fortinet com...
Page 706: ...www fortinet com...