Cisco Cisco Email Security Appliance C650 Guía Del Usuario
8-8
Cisco IronPort AsyncOS 7.6 for Email Configuration Guide
OL-25136-01
Chapter 8 Anti-Virus
You can view the Updater Logs to verify whether or not the antivirus files have been successfully
downloaded, extracted, or updated. Use the
downloaded, extracted, or updated. Use the
tail
command to show the final entries in the Updater log
subscription to ensure that virus updates were obtained.
Configuring Virus Scanning Actions for Users
Once enabled globally, the virus scanning engine integrated into the Cisco IronPort appliance processes
messages for viruses for incoming and outgoing mail based on policies (configuration options) you
configure using the Email Security Manager feature. You enable Anti-Virus actions on a per-recipient
basis using the Email Security Feature: the Mail Policies > Incoming or Outgoing Mail Policies pages
(GUI) or the
messages for viruses for incoming and outgoing mail based on policies (configuration options) you
configure using the Email Security Manager feature. You enable Anti-Virus actions on a per-recipient
basis using the Email Security Feature: the Mail Policies > Incoming or Outgoing Mail Policies pages
(GUI) or the
policyconfig > antivirus
command (CLI).
Message Scanning Settings
•
Scan for Viruses Only:
Messages processed by the system are scanned for viruses. Repairs are not attempted for infected
attachments. You can choose whether to drop attachments and deliver mail for messages that contain
viruses or could not be repaired.
attachments. You can choose whether to drop attachments and deliver mail for messages that contain
viruses or could not be repaired.
•
Scan and Repair Viruses:
Messages processed by the system are scanned for viruses. If a virus is found in an attachment, the
system will attempt to “repair” the attachment.
system will attempt to “repair” the attachment.
•
Dropping Attachments
You can choose to drop infected attachments.
When infected attachments to messages have been scanned and dropped by the anti-virus scanning
engine, the attachment is replaced with a new attachment called “Removed Attachment.” The
attachment type is text/plain and contains the following:
engine, the attachment is replaced with a new attachment called “Removed Attachment.” The
attachment type is text/plain and contains the following:
example.com> antivirusupdate
Choose the operation you want to perform:
- MCAFEE - Request updates for McAfee Anti-Virus
- SOPHOS - Request updates for Sophos Anti-Virus
>sophos
Requesting check for new Sophos Anti-Virus updates
example.com>
This attachment contained a virus and was stripped.
Filename: filename
Content-Type: application/filetype