Fortinet white logo
Fortinet white logo

CLI reference

config system fortigate settings

config system fortigate settings

Use this command to configure settings for FortiGate inline blocking. As of FortiOS 7.0.1, FortiGate can send files and get the verdict from FortiNDR directly via the HTTP/2 protocol after FortiNDR joins the Security Fabric.

Syntax

config system fortigate settings

set timeout <timeout_int>

set block-risk-level {low, medium, high, critical}

set block-confidence-level {low, medium, high, critical}

end

Variable

Description

Default

timeout <timeout_int>

The maximum wait time for FortiNDR to send the verdict back to FortiGate.

Timeout set to 0 means FortiNDR not wait for the verdict and only use cache detection. Cache detection refers to the previous verdict or preload detections.

1

Block-risk-level {low, medium, high, critical}

FortiNDR will send block request to FortiGate when a malicious file is detected with a risk level and confidence level at or above the configured value.

medium

Block-confidence-level {low, medium, high, critical}

FortiNDR will send block request to FortiGate when a malicious file is detected with a risk level and confidence level at or above the configured value.

medium

config system fortigate settings

config system fortigate settings

Use this command to configure settings for FortiGate inline blocking. As of FortiOS 7.0.1, FortiGate can send files and get the verdict from FortiNDR directly via the HTTP/2 protocol after FortiNDR joins the Security Fabric.

Syntax

config system fortigate settings

set timeout <timeout_int>

set block-risk-level {low, medium, high, critical}

set block-confidence-level {low, medium, high, critical}

end

Variable

Description

Default

timeout <timeout_int>

The maximum wait time for FortiNDR to send the verdict back to FortiGate.

Timeout set to 0 means FortiNDR not wait for the verdict and only use cache detection. Cache detection refers to the previous verdict or preload detections.

1

Block-risk-level {low, medium, high, critical}

FortiNDR will send block request to FortiGate when a malicious file is detected with a risk level and confidence level at or above the configured value.

medium

Block-confidence-level {low, medium, high, critical}

FortiNDR will send block request to FortiGate when a malicious file is detected with a risk level and confidence level at or above the configured value.

medium