Configuring profiles : Configuring antivirus profiles and antivirus action profiles : Configuring antivirus action profiles
Configuring antivirus action profiles
Go to Profile > Antivirus > Action to define one or more actions that the FortiMail unit should do if the antivirus profile determines that an email is infected by viruses.
 
If any of the antivirus actions is triggered, the content and antispam scans will be skipped.
To access this part of the web UI, your administrator account’s access profile must have Read or Read-Write permission to the Policy category. For details, see “About administrator account permissions and domains”.
To view and configure antivirus action profiles
1. Go to Profile > AntiVirus > Action.
 
GUI item
Description
Domain
(drop-down list)
Select System to see profiles for the entire FortiMail unit, or select a protected domain name to see profiles for that domain. You can see only the domains that are permitted by your administrator profile.
Profile Name
Displays the name of the profile.
Domain
(column)
Displays either System or a domain name.
(Green dot in column heading)
Indicates whether or not the entry is currently referred to by another item in the configuration. If another item is using this entry, a red dot appears in this column, and the entry cannot be deleted.
2. Either click New to add a profile or double-click an existing profile to modify it.
A dialog appears.
3. Configure the following:
 
GUI item
Description
Domain
Select if the action profile will be system-wide or domain-wide.
You can see only the domains that are permitted by your administrator profile.
Profile name
For a new profile, enter a name.
Tag email’s subject line
Enable and enter the text that appears in the subject line of the email, such as [virus], in the With value field. The FortiMail unit will prepend this text to the subject line of spam before forwarding it to the recipient.
Many email clients can sort incoming email messages into separate mailboxes, including a spam mailbox, based on text appearing in various parts of email messages, including the subject line. For details, see the documentation for your email client.
Insert new header
Enable and enter the message header key in the field, and the values in the With value field. The FortiMail unit adds this text to the message header of the email before forwarding it to the recipient.
Many email clients can sort incoming email messages into separate mailboxes, including a spam mailbox, based on text appearing in various parts of email messages, including the message header. For details, see the documentation for your email client.
Message header lines are composed of two parts: a key and a value, which are separated by a colon. For example, you might enter:
X-Custom-Header: Detected as virus by profile 22.
If you enter a header line that does not include a colon, the FortiMail unit will automatically append a colon, causing the entire text that you enter to be the key.
Note: Do not enter spaces in the key portion of the header line, as these are forbidden by RFC 2822.
Deliver to alternate host
Enable to route the email to a specific SMTP server or relay, then type the fully qualified domain name (FQDN) or IP address of the destination.
Note: If you enable this setting, the FortiMail unit uses this destination for all email that matches the profile and ignores Relay server name and Use this domain’s SMTP server to deliver the mail.
BCC
Enable to send a blind carbon copy (BCC) of the email.
Configure BCC recipient email addresses by entering each one and clicking Create in the BCC area.
Notify with profile
Enable and select a notification profile to send a notification email to the sender, recipient, or any other people as you configure in the notification profile. The notification email is customizable and will tell the users what happened to the email message. For details about notification profiles and email templates, see “Configuring notification profiles” and “Customizing email templates”.
Reject
Enable to reject the email and reply to the SMTP client with SMTP reply code 550.
Discard
Enable to accept the email, but then delete it instead of delivering the email, without notifying the SMTP client.
System Quarantine
Enable to redirect email to the system quarantine. For more information, see “Managing the system quarantine”.
Replace infected/suspicious body or attachment(s)
Replaces the infected file with a replacement message that notifies the email user the infected file was removed. You can customize replacement messages. For more information, see “Customizing GUI, replacement messages and email templates”.
Rewrite recipient email address
Enable to change the recipient address of any infected email message.
Configure rewrites separately for the local-part (the portion of the email address before the '@' symbol, typically a user name) and the domain part (the portion of the email address after the '@' symbol). For each part, select either:
None: No change.
Prefix: Prepend the part with text that you have entered in the With field.
Suffix: Append the part with the text you have entered in the With field.
Replace: Substitute the part with the text you have entered in the With field.
Repackage email with customized content
Enable to forward the infected email as an attachment with the customized email body that you define in the custom email template. For example, in the template, you may want to say “The attached email is infected by a virus”. For details, see “Customizing email templates”.
Repackage email with original content
Enable to forward the infected email as an attachment but the original email body will still be used without modification.