Per-site bypassing of scanning

This page includes:

About per-site bypassing of scanning

You can limit the scans that are performed when browsing using an FortiMail Browser Security-protected browser. To limit the scans, you create a scan bypass list. The scan bypass list acts as follows:

  • Download file scanning: By default, when a file is downloaded, the file is scanned by Fortinet to check if the file is malicious. Files that are downloaded from any site that is included in the scan bypass list are not scanned.

    Note: When a file is downloaded from a site on the scan bypass list, the download is performed immediately - irrespective of any other download configurations that may be set.

  • Website scanning: All sites that are included in the scan bypass list are not scanned when they are browsed using an FortiMail Browser Security-protected browser.

Note: For all sites included in the scan bypass list: no scans are performed on these sites, no scans are performed on any files that are downloaded from these sites - and no data is sent to Fortinet from any of these sites.

Configuring per-site bypassing of scanning

You'll need to configure the advanced feature below to implement per-site bypassing of download scanning and website scanning. For details on how to add an advanced feature, see Advanced Features.

Advanced feature

Description

localDomainWhitelist

Specifies the scan bypass list - the list of sites on which scanning is not performed. For details about the scan bypass list, see About per-site bypassing of scanning above.

Default: blank - all downloads are scanned.

Use commas to specify multiple sites. You can add a space after the comma [optional].

The following example:

  • prevents scanning of downloads from acme.com and MySecureSite.com, and allows scanning of downloads from all other sites.

  • prevents scanning of both acme.com and MySecureSite.com - when these sites are browsed using an FortiMail Browser Security-protected browser.

acme.com, MySecureSite.com

  • Wildcard characters [*] are supported.

  • CIDR suffixes are not supported. For example, 10.0.0.0/8 is not supported.