When the Email Security - Server appliance is deployed in monitor mode or block mode and Advanced URL Defense is enabled, you can use the CLI to enable the Email Security - Server appliance to rewrite the URLs within a message. In the following example, the Email Security - Server appliance adds protect2.fireeye.com to the rewritten URL:
https://protect2.fireeye.com/url?k=df35d163-2d4a-45fb-8df2-62d3517eae72&u=http://protection-update.team.com1serv13.webs001cr-cm-l0gin-submit-id.app1-lo0gin-submit-id.pp1-login-login-2014.ap.serv64.idmsa-protection.com
To prevent URLs from being rewritten multiple times, the Email Security - Server appliance checks to see if the URL already begins with the rewritten host prefix. If the URL already contains this host prefix, then the URL is not rewritten again. You can use the CLI to whitelist specific URLs. Whitelisting the URLs exempts them from the URL rewrite prevention checks.
For information on enabling Advanced URL Defense, see Enabling or disabling advanced URL defense.
For information on enabling block mode, see Analysis modes.
Caution
If you do not enable rewriting URLs, emails containing a URL will be delivered to you with the links intact. If a verdict is returned later from FAUDE that the email is malicious, your system will not be protected if you click on the link.
Prerequisites
Administrator or Operator access to the appliance
Enable block mode using the
email-analysis mode blockcommand. For details about this command, refer to the Trellix CLI Reference.Enable Advanced URL Defense. For details, see Enabling or disabling advanced URL defense.