Course menu

Module 6: Security ProfilesLesson 6.5 (5 of 6 in this module)28 of 33 in the FortiGate Administrator course

Antivirus and IPS

Scanning files with FortiGuard antivirus, protecting clients and servers with IPS sensors, signature actions, and checking signature versions.

Intermediate · 12 min read

What you will learn

After this lesson, you can apply antivirus and IPS to outbound and inbound policies, choose IPS signatures by filter, test detection safely, and confirm the signatures are current.

  • Antivirus
  • IPS sensors
  • Signature actions
  • Updates

Antivirus and IPS are the two FortiGate profiles that look for attacks in content. Antivirus scans files carried by web, mail and file-transfer protocols against FortiGuard malware signatures. IPS (intrusion prevention) compares traffic with signatures of known exploits and attack patterns against clients and servers, and blocks or resets matching sessions.

In simple terms: Antivirus looks for bad files; IPS looks for attacks, such as someone trying to break into the web server.

A real-life situation

WEB1 is now reachable from the Internet, and within hours its logs fill with scans for well-known web application exploits. Meanwhile a staff member downloads an invoice that is really malware. FGT1 already allows both sessions; antivirus and IPS decide whether the content inside them gets through.

Antivirus

Simplified illustration of the FortiOS 7.4 GUI · not a screenshot
FGT1Security Profiles › AntiVirus

Edit AntiVirus Profile: default

Feature set
Flow-based Proxy-based

Inspected Protocols

Protocols
HTTP SMTP POP3 IMAP FTP CIFS

APT Protection Options

Use FortiGuard outbreak prevention database
On
Treat Windows executables in email attachments as viruses
Off
  • Infected files are blocked and the user sees a replacement page instead; the event is logged with the virus name.
  • HTTPS downloads are only scanned with deep inspection.
  • Very large files, or archives too deep to unpack, are handled by oversize settings (pass or block); know which your profile uses.

IPS sensors

An IPS sensor selects signatures with filters (severity, target client or server, operating system, protocol) and sets an action for them. Built-in sensors cover the common cases:

SensorUse on
defaultGeneral traffic: critical, high and medium severity signatures
protect_clientOutbound policies: attacks against users' browsers and apps
protect_http_serverInbound policies to web servers, such as Internet-to-WEB1
high_securityStrict environments: blocks more signatures, more false positives
config firewall policy edit 3 set ips-sensor "protect_client" set av-profile "default" next edit 6 set ips-sensor "protect_http_server" set ssl-ssh-profile "WEB1-inbound" next end

Policy 3 (LAN-to-Internet) protects users; policy 6 (Internet-to-WEB1) protects the server. WEB1-inbound is an SSL inspection profile with WEB1's own certificate, so IPS can see attacks inside HTTPS.

IPS also includes rate-based signatures (for brute-force and flood patterns) and a botnet option that blocks connections to known command-and-control servers.

Testing safely

  • Antivirus: download the EICAR test file from a trusted source over HTTP (and over HTTPS once deep inspection is on). It is a harmless text string that all scanners detect by agreement.
  • IPS: check Log & Report › Security Events › Intrusion Prevention after a vulnerability scan of WEB1 that you have permission to run.
  • Never test with real malware.

Are the signatures current?

diagnose autoupdate versions lists the AV and IPS engine and database versions and when they last updated; System › FortiGuard shows the licences. Outdated signatures are almost as bad as none.

Why it works this way

Attacks travel inside allowed traffic: malware in a normal-looking download, exploits in normal-looking web requests. Only content inspection can see them, and only signatures that are current can recognise them. Choosing IPS signatures by target keeps inspection relevant: a web server doesn't need browser-exploit signatures, and a laptop doesn't need server-side ones.

Common mistakes

  • Putting a server-protection sensor on outbound user traffic, or the other way round.
  • Forgetting that encrypted traffic needs inspection for AV and IPS to work.
  • Letting the FortiGuard licence lapse.
  • Testing with live malware instead of EICAR.

Key takeaways

✅ Key takeaways
  • Antivirus scans files in web, mail and file transfers; IPS matches exploit and attack signatures.
  • IPS sensors select signatures by filters; built-in sensors suit clients and servers.
  • Inbound HTTPS to your server can be inspected with its own certificate.
  • Test with EICAR and scans you are allowed to run; check signature versions regularly.

Check yourself

Predict · scenario 1

Which IPS sensor belongs on the Internet-to-WEB1 policy?

Predict · scenario 2

How do you check antivirus detection without risking a real infection?

Predict · scenario 3

An attack against WEB1 inside HTTPS isn't detected by IPS. What is needed?

FAQ

Does FortiGate antivirus replace endpoint antivirus?
No. It stops known malware crossing the firewall, but not malware arriving by USB stick, inside traffic the FortiGate can't decrypt, or between hosts on the same LAN. Use both.
Should IPS be set to block everything?
Start from the built-in sensors, whose signatures use Fortinet's recommended (default) action, and monitor new custom sensors before blocking. Blocking every signature regardless of target causes false positives and slows inspection.