- May 8, 2015
- 881
What do you think of these two products (Forticlient AV and PrivateFirewall) ?
Well Forticlient is a pretty good middle ground between basic and advanced AV. I'd consider it advanced if you use the new feature that they integrated (FortiSandbox) which I believe you need FortiOS to use. Apparently it is usable in a VM environment. Forticlient has a great AV with great web blocking. Without the sandbox I'd imagine heuristics is it's only real defense against unknown threats. Not much else to say about it.
Privatefirewall doesn't take much editing in it's configuration to be aggressive. Unlike using some other AV with it, Privatefirewall asked a lot of questions about Forticlient while installing so you'll have to turn on training mode to avoid any problems. You should do that regardless of the AV though. I can't give too much of a judgement on this product since I've only seen about 4 of it's features come into play. All of which worked as advertised so I have a pretty good opinion of it. On Windows 8/10 I had some problems of system lockups. Using Windows 7 right now.
Each of the modules gave enough information for the most part to give me an idea of why it detected a behavior or actions that took place. The features I encountered so far include firewall, System Anomaly Detection, Advanced Application Control, and Process Control & Protection. There is a possibility that some of these features that they list are working together in order to be effective such as Advanced Reporting module being used to show case information to the user upon detection by one of it's components. No idea if things like web blocking work. Forticlient is probably one of the best (and most aggressive) web blockers I've ever used. Might not be anything to block by Privatefirewall. I'm not even sure if this has some preset list of trust/untrusted applications or connections or if it just has a list of actions or connections protocols, ports, etc that it deems unsafe or suspicious.
Have not experienced any slow downs with either (unless your using Privatefirewall on Windows 8/10 or using old version of Forticlient (like 5.2 - current version is 5.4). Version 5.2 had a problem where you could either no turn off logging (using a lot of disk and moderate - high CPU) or you could turn it off and it would still show it's logging process taking up massive system resources. 5.4 doesn't do that. Plus as I said, it integrated sandboxing but seems to need an IP address from a FortiOS install on physical computer or VM. Watching some of the videos on YouTube from the company has shown that the FortiSandbox is far more complicated than other sandboxes like Comodo Sandbox. Could potentially be better in mitigating threats as well. It actually records every little thing a file does such as dropped file locations, etc. It's pretty cool (kind of like running a file on those sites like Malwr except not painfully slow). Wondering if you could run the file directly into the sandbox (via context menu, etc) or does it run it on your computer and watch/isoloate the file.
Sorry, this is more of a run through of what I know more than what I think of these products. May contain a lot of mistakes.