Cisco Cisco Email Security Appliance C160 Mode D'Emploi

Page de 1185
 
16-5
Cisco AsyncOS 8.5.6 for Email User Guide
 
Chapter 16      File Reputation Filtering and File Analysis
  Configuring File Reputation and Analysis Features
Step 6
(Optional) Adjust the Advanced settings for the reputation query:
Step 7
Submit and commit your changes. 
Configuring the Incoming Mail Policy for File Reputation Scanning and File 
Analysis 
Procedure 
Step 1
Select Mail Policies > Incoming Mail Policies.
Step 2
Click the link in the Advanced Malware Protection column of the mail policy to modify. 
Step 3
Choose options. 
If you do not want to send files to the cloud, for example for confidentiality reasons, deselect Enable 
File Analysis
Attachments are considered "Unscannable" when the appliance is unable to obtain information from 
the file reputation service for any reason, for example because the connection timed out. 
Archived messages will be stored as an mbox-format log file in the 
amparchive
 directory on the 
appliance. The preconfigured AMP Archive (amparchive) log subscription is required. 
To perform an action not directly available on this page, see the configuration example at 
Step 4
Submit and commit your changes. 
Quarantining Messages with Attachments Sent for Analysis: X-Header 
Configuration Example
To quarantine messages with attachments that have been sent for analysis, use an X-Header or Custom 
Header and content filters. 
Option
Description
SSL Communication for File Reputation
Check Use SSL (Port 443) to communicate on port 443 
instead of the default port, 32137.
This option also allows you to configure an upstream proxy 
for file reputation.
Note
SSL communication over port 32137 may require 
you to open that port in your firewall.
Reputation Threshold
Use value from Cloud Service
Enter custom value
The upper limit for acceptable file reputation scores. 
Scores above this threshold indicate the file is infected.