Cisco Cisco Email Security Appliance C160 Mode D'Emploi

Page de 1224
 
17-8
Cisco AsyncOS 9.5 for Email User Guide
 
Chapter 17      File Reputation Filtering and File Analysis
  Configuring File Reputation and Analysis Features
Step 3
Choose options.
If you do not have an on-premises Cisco AMP Threat Grid Appliance and you do not want to send 
files to the cloud, for example for confidentiality reasons, uncheck Enable File Analysis.
Select the actions that AsyncOS must perform if an attachment is considered Unscannable. 
Attachments are considered Unscannable when the appliance is unable to obtain information from 
the file reputation service for any reason, for example because the connection timed out. 
Select the following:
Whether to deliver or drop the message.
Whether to archive the original message. Archived messages are stored as an mbox-format log 
file in the 
amparchive
 directory on the appliance. The preconfigured AMP Archive 
(
amparchive
) log subscription is required.
Whether to warn the end user by modifying the message subject, for example, [WARNING: 
ATTACHMENT(S) MAY CONTAIN MALWARE].
Whether to add a custom header to provide granular controls to the administrator.
Select the actions that AsyncOS must perform if an attachment is considered Malicious. Select the 
following:
Whether to deliver or drop the message.
Whether to archive the original message. Archived messages are stored as an mbox-format log 
file in the 
amparchive
 directory on the appliance. The preconfigured AMP Archive 
(
amparchive
) log subscription is required.
Whether to deliver the message after removing the malware attachments.
Whether to warn the end user by modifying the message subject, for example, [WARNING: 
MALWARE DETECTED IN ATTACHMENT(S)].
Whether to add a custom header to provide granular controls to the administrator.
Select the actions that AsyncOS must perform if an attachment is sent for File Analysis. Select the 
following:
Whether to deliver or quarantine the message.
Whether to archive the original message. Archived messages are stored as an mbox-format log 
file in the 
amparchive
 directory on the appliance. The preconfigured AMP Archive 
(
amparchive
) log subscription is required.
Whether to warn the end user by modifying the message subject, for example, “
[WARNING: 
ATTACHMENT(S) MAY CONTAIN MALWARE]
.”
Whether to add a custom header to provide granular controls to the administrator.
Step 4
Submit and commit your changes. 
Quarantining Messages with Attachments Sent for Analysis
You can configure the appliance to quarantine files sent for analysis instead of releasing them 
immediately to the workqueue. Quarantined messages and their attachments are rescanned for threats 
upon release from quarantine. If the message is released after file analysis results are available to the 
reputation scanner, any identified threats will be caught during rescanning.