Cisco Cisco Email Security Appliance C170 Guia Do Utilizador

Página de 630
Chapter 9      Anti-Virus
9-312
Cisco IronPort AsyncOS 7.1 for Email Configuration Guide
OL-22158-02
The 
antivirus
 log can be used to verify that all individual identity files based on 
filename.ide
 have been successfully downloaded, extracted, or updated. Use the 
tail
 command to show the final entries in any “AntiVirus” log subscription to 
ensure that virus updates were obtained. 
Configuring Virus Scanning Actions for Users
Once enabled globally, the virus scanning engine integrated into the IronPort 
appliance processes messages for viruses for incoming and outgoing mail based 
on policies (configuration options) you configure using the Email Security 
Manager feature. You enable Anti-Virus actions on a per-recipient basis using the 
Email Security Feature: the Mail Policies > Incoming or Outgoing Mail Policies 
pages (GUI) or the 
policyconfig -> antivirus
 command (CLI). 
Message Scanning Settings
Scan for Viruses Only:
Messages processed by the system are scanned for viruses. Repairs are not 
attempted for infected attachments. You can choose whether to drop 
attachments and deliver mail for messages that contain viruses or could not 
be repaired.
Scan and Repair Viruses:
Messages processed by the system are scanned for viruses. If a virus is found 
in an attachment, the system will attempt to “repair” the attachment. 
Dropping Attachments 
You can choose to drop infected attachments. 
When infected attachments to messages have been scanned and dropped by 
the anti-virus scanning engine, the attachment is replaced with a new 
attachment called   “Removed Attachment.” The attachment type is text/plain 
and contains the following:
This attachment contained a virus and was stripped.