Cisco Cisco Web Security Appliance S690 Guida Utente

Pagina di 450
 
14-15
AsyncOS 9.0 for Cisco Web Security Appliances User Guide
 
Chapter 14      File Reputation Filtering and File Analysis
  Troubleshooting File Reputation and Analysis
Check for network issues that may prevent the appliance from communicating with the cloud 
services. 
Increase the Query Timeout value: 
Select Security Services > Anti-Malware and Reputation . The Query Timeout value is in the 
Advanced settings area of the Advanced Malware Protection Services section. 
API Key Error (On-Premises File Analysis) 
Problem
You receive an API key alert when attempting to view File Analysis report details, or the  Web 
Security appliance is unable to connect to the AMP Threat Grid server to upload files for analysis. 
Solution
This error can occur if you change the hostname of the AMP Threat Grid server and you are 
using a self-signed certificate from the AMP Threat Grid server, as well as possibly under other 
circumstances. To resolve the issue: 
Generate a new certificate from the AMP Threat Grid appliance that has the new hostname. 
Upload the new certificate to the  Web Security appliance. 
Reset the API key on the AMP Threat Grid appliance. For instructions, see the online help on the 
AMP Threat Grid appliance. 
Related Topics 
Files are Not Uploaded As Expected 
Problem
Files are not evaluated or analyzed as expected. There is no alert or obvious error. 
Problem
Consider the following: 
The file may have been sent for analysis by another appliance and thus already be present on the File 
Analysis server or in the cache of the appliance that is processing the file. 
Check the maximum file size limit configured for the DVS Engine Object Scanning Limits on the 
Security Services > Anti-Malware and Reputation page. This limit applies to Advanced Malware 
Protection features. 
File Analysis Details in the Cloud Are Incomplete 
Problem
Complete file analysis results in the public cloud are not available for files uploaded from other 
Web Security appliances in my organization. 
Solution
Be sure to group all appliances that will share file analysis result data. See 
. This configuration must be done on 
each appliance in the group.