FORTIGUARD® SERVICES
Fortinet® security products offer dynamic protection based on the work of the dedicated Fortinet® Global Security Research Team, which researches and develops protection against known and potential security threats. Their research forms the basis of the FortiGuard Security Subscription Services, which deliver continuous, automated updates for antivirus, intrusion prevention, Web filtering, antispam, vulnerability and compliance management, application control, and database security services.
FortiGuard Benefits
- Global, proactive threat library delivers comprehensive protection against network, content, and application threats.
- Multi-threat security research leverages intelligence from multiple security disciplines to protect against known and potential threats.
- Feedback from worldwide installed base plus cooperation with major infrastructure vendors provides broadest protection against attacks and exploits.
- Real-time updates - both push and pull - keep your defenses ahead of the threats with industry-leading threat response time with optional Service Level Agreements (SLAs).
- Simple setup offers true "set and forget" functionality for easier deployment and management.
- Device-based licensing eliminates per-user fees for significantly lower entry and ongoing maintenance costs.
FortiGuard Security Subscription Services Available
Fortinet delivers dynamic signature datasets that are optimized for each Fortinet platform:
| Platform |
Anti-
virus |
IPS |
Anti-
spam |
Web
Filtering |
Appli-
cation
Control |
Data-
base |
Vulner-
ability
Management |
| FortiGate |
Yes |
Yes |
Yes |
Yes |
Yes |
- |
- |
| FortiAnalyzer |
- |
- |
- |
- |
- |
- |
Yes |
| FortiClient |
Yes |
- |
Yes |
Yes |
- |
- |
- |
| FortiDB |
- |
- |
- |
- |
- |
Yes |
- |
| FortiMail |
Yes |
- |
Yes |
- |
- |
- |
- |
| FortiScan |
- |
- |
- |
- |
- |
- |
Yes |
Antivirus/Antispyware
The FortiGuard Antivirus Service employs advanced virus, spyware, and heuristic detection engines to enable FortiGate, FortiWiFi, and FortiMail appliances and FortiClient end point security agents to prevent both new and evolving virus, spyware, and malware threats and vulnerabilities from gaining access to your network and its valuable content and applications. Fortinet provides the industry's fastest response and global updates via the FortiGuard global distribution network for comprehensive protection against all content-level threats.
Intrusion Prevention
The FortiGuard Intrusion Prevention Service (IPS) uses a customizable database of thousands of vulnerabilities to enable FortiGate and FortiWiFi appliances to stop attacks that evade conventional firewall defenses. It also provides anomaly-based detection, enabling the system to recognize threats for which no signature has yet been developed. The combination of known and potential threat prevention enables FortiGate systems to stop the most damaging attacks at the network border regardless of whether the network is a wired, wireless, partner extranet, or branch office network connection. IPS signatures are continuously updated via the global FortiGuard distribution network.
Antispam
The FortiGuard Antispam Service uses both a sender IP reputation database and a spam signature database, along with sophisticated spam filtering tools on Fortinet appliances and agents, to detect and block a wide range of spam messages. On FortiGate or FortiMail systems, FortiGuard Antispam Service can dramatically reduce the amount of spam messages that your email servers process, and enable FortiClient end point security agents to block spam on remote PCs and mobile devices. Customizable policies enable antispam filtering policy-setting for each domain, group of users, and individual users, and dual-pass detection technology significantly reduces spam volume at the perimeter for superior control of email attacks and infections. Updates to the IP reputation spam signature databases are provided continuously via the global FortiGuard global distribution network.
Web Filtering
The FortiGuard Web Filtering Service enables FortiGate and FortiWifi appliances and FortiClient end point security agents to block access to harmful, inappropriate, and dangerous websites which may contain phishing/pharming attacks, malware such as spyware, or objectionable content that can expose your organization to legal liability. Based on automatic research tools and targeted research analysis, real-time updates enable you to apply highly-granular policies that filter web access based on 77 web content categories, over 30 million rated websites, and more than two billion web pages - all continuously updated via the FortiGuard global distribution network.
Application Control
Application Control (AC) protects managed desktops and servers by allowing or denying network application usage based on policies established by the network administrator. FortiGuard Application Control detection signatures identify Enterprise applications, databases, web mail, social networking applications, IM/P2P, and file transfer protocols and place them under the control of protection profiles. Network security managers can create whitelists, blacklists, or combinations to provide exactly the right level of protection their organization needs. The inherent synergies between Fortinet's antivirus and application control solutions provide the highest levels of protection and control. Application Control signatures are continuously developed and delivered through the FortiGuard global distribution network.
Database Security
FortiDB database security products offer centrally-managed, enterprise-scale, database hardening. Integral to their power are hundreds of pre-installed policies that cover known exploits, configuration weaknesses, OS issues, operational risks, and data access privileges. The FortiGuard Database Policies Service is automatically updated with the latest regulatory/industry best practices by means of the FortiGuard global distribution network. Policies are easily run to verify that databases conform to corporate standard configurations, implement tests for custom applications, or conduct extended penetration testing.
Vulnerability Management
Vulnerability Management (VM) enables organizations to minimize the risk of vulnerabilities by quickly discovering vulnerabilities, measuring the potential risk, and then providing the information necessary to mitigate those risks. Additionally, a compliance reporting function provides organizations with actionable reports that can identify areas for remediation.