Chapter 10 Install and System Administration for FortiOS 5.0 : Advanced concepts : Replacement messages list : Replacement message tags
  
Replacement message tags
Replacement messages can include replacement message tags, or variables. When users receive the message, the message tag is replaced with content relevant to the message. The table lists the replacement message tags that you can use.
Table 70: Replacement message tags  
Tag
Description
%%AUTH_LOGOUT%%
The URL that will immediately delete the current policy and close the session. Used on the auth-keepalive page.
%%AUTH_REDIR_URL%%
The auth-keepalive page can prompt the user to open a new window which links to this tag.
%%CATEGORY%%
The name of the content category of the web site.
%%DEST_IP%%
The IP address of the request destination from which a virus was received. For email this is the IP address of the email server that sent the email containing the virus. This tag only works with alert email replacement messages.
%%DURATION%%
(FortioS Carrier only)
The amount of time in the reporting period. This is user defined in the protection profile.
%%EMAIL_FROM%%
The email address of the sender of the message from which the file was removed.
%%EMAIL_TO%%
The email address of the intended receiver of the message from which the file was removed.
%%FAILED_MESSAGE%%
The failed to login message displayed on the auth-login-failed page.
%%FILE%%
The name of a file that has been removed from a content stream. This could be a file that contained a virus or was blocked by antivirus file blocking. %%FILE%% can be used in virus and file block messages.
%%FORTIGUARD_WF%%
The FortiGuard - Web Filtering logo.
%%FORTINET%%
The Fortinet logo.
%%LINK%%
The link to the FortiClient Host Security installs download for the Endpoint Control feature.
%%HTTP_ERR_CODE%%
The HTTP error code. “404” for example.
%%HTTP_ERR_DESC%%
The HTTP error description.
%%KEEPALIVEURL%%
(FortiOS Carrier only)
auth-keepalive-page automatically connects to this URL every %%TIMEOUT%% seconds to renew the connection policy.
%%MMS_SENDER%%
(FortiOS Carrier only)
Senders MSISDN from message header.
%%MMS_RECIPIENT%%
(FortiOS Carrier only)
Recipients MSISDN from message header.
%%MMS_SUBJECT%%
(FortiOS Carrier only)
MMS Subject line to help with message identity.
%%MMS_HASH_CHECKSUM%%
Value derived from hash calculation - will only be shown on duplicate message alerts.
%%MMS_THRESH%%
Mass MMS alert threshold that triggered this alert.
%%NIDSEVENT%%
The IPS attack message. %%NIDSEVENT%% is added to alert email intrusion messages.
%%NUM_MSG%%
(FortiOS Carrier only)
The number of time the device tried to send the message with banned content within the reporting period.
%%OVERRIDE%%
The link to the FortiGuard Web Filtering override form. This is visible only if the user belongs to a group that is permitted to create FortiGuard web filtering overrides.
%%OVRD_FORM%%
The FortiGuard web filter block override form. This tag must be present in the FortiGuard Web Filtering override form and should not be used in other replacement messages.
%%PROTOCOL%%
The protocol (http, ftp, pop3, imap, or smtp) in which a virus was detected. %%PROTOCOL%% is added to alert email virus messages.
%%QUARFILENAME%%
The name of a file that has been removed from a content stream and added to the quarantine. This could be a file that contained a virus or was blocked by antivirus file blocking. %%QUARFILENAME%% can be used in virus and file block messages. Quarantining is only available on FortiGate units with a local disk.
%%QUOTA_INFO%%
Display information about the traffic shaping quota setting that is blocking the user. Used in traffic quota control replacement messages.
%%QUESTION%%
Authentication challenge question on auth-challenge page.
Prompt to enter username and password on auth-login page.
%%SERVICE%%
The name of the web filtering service.
%%SOURCE_IP%%
The IP address of the request originator who would have received the blocked file. For email this is the IP address of the user’s computer that attempted to download the message from which the file was removed. This tag only works with alert email replacement messages.
%%TIMEOUT%%
Configured number of seconds between authentication keepalive connections. Used on the auth-keepalive page.
%%URL%%
The URL of a web page. This can be a web page that is blocked by web filter content or URL blocking. %%URL%% can also be used in http virus and file block messages to be the URL of the web page from which a user attempted to download a file that is blocked.
%%VIRUS%%
The name of a virus that was found in a file by the antivirus system. %%VIRUS%% can be used in virus messages