Fortinet black logo

Administration Guide

Sandbox Detection

Sandbox Detection

FortiClient supports integration with FortiSandbox, including on-premise FortiSandbox appliances and FortiClient Cloud Sandbox. When configured, FortiSandbox automatically scans files downloaded on the endpoint or from removable media attached to the endpoint or mapped network drives. FortiClient also automatically scans files downloaded with an email client on the endpoint or from the Internet. In each case, if the file is not detected locally, and FortiSandbox integration is configured, FortiClient sends the file to the FortiSandbox for further analysis. Endpoint users can also manually submit files to FortiSandbox for scanning.

You can block access to files until FortiClient returns the FortiSandbox scanning result.

When scanning is complete, FortiClient can quarantine/deny access to infected files or alert and notify the endpoint user of infected files without quarantining the files. If FortiSandbox sends a verdict to FortiClient indicating that the file is malicious, FortiClient also sends the results to EMS.

As FortiSandbox receives files for scanning from various sources, it collects and generates AV signatures for such samples. FortiClient periodically downloads the latest AV signatures from FortiSandbox, and applies them locally to all realtime and on-demand AV scanning.

FortiClient can send a maximum of 300 files daily to FortiClient Cloud Sandbox. If multiple files are submitted around the same time, FortiClient sends one file to FortiClient Cloud Sandbox, waits until it receives the verdict for that file, then sends the next file to FortiClient Cloud Sandbox.

The file size limit for submission to FortiSandbox is 200 MB.

note icon

If configured by the EMS administrator, FortiClient submits files with specified extensions to FortiSandbox. See the FortiClient EMS Administration Guide for details.

Note

FortiSandbox integration does not require FortiClient real-time protection to be enabled. If using a separate real-time antimalware application, FortiClient cannot send files that this application has quarantined to FortiSandbox.

Sandbox Detection

Sandbox Detection

FortiClient supports integration with FortiSandbox, including on-premise FortiSandbox appliances and FortiClient Cloud Sandbox. When configured, FortiSandbox automatically scans files downloaded on the endpoint or from removable media attached to the endpoint or mapped network drives. FortiClient also automatically scans files downloaded with an email client on the endpoint or from the Internet. In each case, if the file is not detected locally, and FortiSandbox integration is configured, FortiClient sends the file to the FortiSandbox for further analysis. Endpoint users can also manually submit files to FortiSandbox for scanning.

You can block access to files until FortiClient returns the FortiSandbox scanning result.

When scanning is complete, FortiClient can quarantine/deny access to infected files or alert and notify the endpoint user of infected files without quarantining the files. If FortiSandbox sends a verdict to FortiClient indicating that the file is malicious, FortiClient also sends the results to EMS.

As FortiSandbox receives files for scanning from various sources, it collects and generates AV signatures for such samples. FortiClient periodically downloads the latest AV signatures from FortiSandbox, and applies them locally to all realtime and on-demand AV scanning.

FortiClient can send a maximum of 300 files daily to FortiClient Cloud Sandbox. If multiple files are submitted around the same time, FortiClient sends one file to FortiClient Cloud Sandbox, waits until it receives the verdict for that file, then sends the next file to FortiClient Cloud Sandbox.

The file size limit for submission to FortiSandbox is 200 MB.

note icon

If configured by the EMS administrator, FortiClient submits files with specified extensions to FortiSandbox. See the FortiClient EMS Administration Guide for details.

Note

FortiSandbox integration does not require FortiClient real-time protection to be enabled. If using a separate real-time antimalware application, FortiClient cannot send files that this application has quarantined to FortiSandbox.