You can configure URL Dynamic Analysis by using the Email Security - Server appliance Web UI or CLI:
When URL Dynamic Analysis (also called DUA) is enabled, the Email Security - Server appliance uses the live ether1 or ether2 interface to retrieve remote objects in a controlled live mode.
If your local network connection accesses the Internet through a proxy server, you must also specify the IPv4 address and the port number for the proxy server. For details about how to specify the proxy server settings, see Configuring a proxy server for URL dynamic analysis using the Web UI or Configuring a proxy server for URL dynamic analysis using the CLI. Proxy authentication settings are optional, depending on the configuration of the proxy server.
Note
URL Dynamic Analysis is disabled by default. After the live ether1 or ether2 data interface is cabled for connectivity to the Internet and you have configured the network settings for the live ether1 or ether2 data interface, you can enable the feature. For details about how to enable URL Dynamic Analysis, see Enabling or disabling URL dynamic analysis. After the feature is enabled, you can validate end-to-end connectivity between the live (ether1 or ether2) interface and the Internet.
Important
If the live ether1 data interface is required, you must configure network settings with the same IP address, mask, default gateway, and name server used for the ether1 (management interface).
Important
By default, traffic on the live ether2 interface is not allowed to reach hosts as defined in RFC 1918 or other hosts in the network range of the external IPv4 address for the live ether2 interface. Trellix recommends that you do not disable the analysis live filters so that malware objects cannot reach the local network.
If the name server and the HTTP proxy server for the live ether2 interface reside in a private subnet, use the
no analysis live filter dest-addr private dropcommand and theno analysis live filter dest-addr external-ip dropcommand to prevent the system from dropping packets on the live ether2 interface, and to prevent the packets from reaching the private destination addresses or the external IPv4 destination addresses of the live interface.
Important
If the appliance is deployed in SPAN/TAP mode, you must use ether2 for the live interface.
Prerequisites
Administrator or Operator access to the Email Security - Server appliance.
An established connection between the Email Security - Server appliance and the Internet.
If the live ether2 data interface is required, verify that the ether2 interface is cabled for connectivity to the Internet directly or through an HTTP proxy server.