In the FortiSandbox settings dialog it is possible to change the following settings concerning FortiSandbox detection engine:
Maximum file size limit
Specifies the maximum file size for which to perform the check by the engine.
Treat oversize as clean
If this is enabled and the check is skipped because the file is too big, the file is considered “clean” (like if the check was performed and found no problems). If this is disabled, then such file is considered “suspicious/dangerous” (like if the check was performed and found a problem) and the whole package will be quarantined.
Block following ratings
The result of a check by the sandbox engine can in case of new unknown threats be one of the following values:
Low risk
Medium risk
High risk
This setting specifies, which of these results are treated as dangerous and will be blocked (quarantined). It is recommended to block medium and high risk results. Low risk is to be considered, as it can be more often a “false positive” result.
Remote access mode
Specifies whether to use HTTP or HTTPS to access the FortiSandbox API. HTTP should be used only in internal networks.
IP address or DNS hostname
IP address or hosname of the FortiSandbox.
TCP port
TCP port on which the FortiSandbox HTTP(S) interface runs.
Username
Username that will be used to access and authenticate to the FortiSandbox API. It is recommended to create a dedicated user for the SOFiE application.
Password
Password, which will be used to authenticate to the FortiSandbox.
Test
Using the Test button it is possible to test the access to the FortiSandbox using the parameters entered above and verify if it works.
This whole settings dialog looks like this:
0 Comments