FortiADC
FortiADC enhances the scalability, performance, and security of your applications whether they are hosted on premises or in the cloud.
kmak
Staff
Staff
Article Id 305470
Description This article describes the steps to identify Antivirus scan error logs and configure the Antivirus Profile limit in FortiADC.
Scope FortiADC.
Solution

Prerequisite:

  • FortiADC Security log is enabled for the Antivirus category.
  • Server Load Balance virtual server should be in profile type L7-TCP, HTTP, HTTPS, or SMTP.

 

FortiADC Server Load Balance with Layer-7 TCP, HTTP, HTTPS, and SMTP profile supports the Antivirus security scans. The default Antivirus Profile has the compressed file size limit, nested compressed file limit, and the file size limit. Hitting the limit will trigger the error log in the Security Log for Antivirus. The error sample and the relative limit settings are listed as follows.

 

The default Antivirus-Profile is not editable, it is mandatory to clone or create a custom Antivirus Profile and include the Antivirus profile in the SLB Virtual Server.

 

  1. Error message 'AV engine meet error: exceed archive decompress size limit'. This error is related to the 'Uncomp Size Limit' setting. The default value of Uncomp Size Limit is 2MB. The valid values range for the limit is from 1 to 2000MB.

    kmak_0-1710916700878.jpeg

 

  1. Error message 'AV engine meet error: exceed archive nested limit, archive corrupted'. This error is related to the 'Uncomp Nest Limit' setting. The default value of Uncomp Nest Limit is 2. The valid values range for the limit is from 2 to 100.

    kmak_1-1710916700887.jpeg

  2. Error message 'AV scan length oversize'. This error is related to the 'Oversize Limit' setting. The default value of the Oversize limit is 1024KB. The valid values range for the limit is from 1 to 12000000KB. For AntiVirus files larger than 1000KB, the device memory must be larger than 32GB to support the scan.

    kmak_2-1710916700892.jpeg
    AntiVirus Profile can be cloned or created in FortiADC -> Network Security -> AntiVirus.

 

kmak_3-1710916700894.jpeg

 

Related document:

Creating an AV profile