Enabling or disabling rewriting URLs

Prev Next

When the Email Security - Server appliance is deployed in monitor mode or block mode and Advanced URL Defense is enabled, you can use the CLI to enable the Email Security - Server appliance to rewrite the URLs within a message. In the following example, the Email Security - Server appliance adds protect2.fireeye.com to the rewritten URL:

https://protect2.fireeye.com/url?k=df35d163-2d4a-45fb-8df2-62d3517eae72&u=http://protection-update.team.com1serv13.webs001cr-cm-l0gin-submit-id.app1-lo0gin-submit-id.pp1-login-login-2014.ap.serv64.idmsa-protection.com

To prevent URLs from being rewritten multiple times, the Email Security - Server appliance checks to see if the URL already begins with the rewritten host prefix. If the URL already contains this host prefix, then the URL is not rewritten again. You can use the CLI to whitelist specific URLs. Whitelisting the URLs exempts them from the URL rewrite prevention checks.

For information on enabling Advanced URL Defense, see Enabling or disabling advanced URL defense.

For information on enabling block mode, see Analysis modes.

Caution

If you do not enable rewriting URLs, emails containing a URL will be delivered to you with the links intact. If a verdict is returned later from FAUDE that the email is malicious, your system will not be protected if you click on the link.

Prerequisites

  • Administrator or Operator access to the appliance

  • Enable block mode using the email-analysis mode block command. For details about this command, refer to the Trellix CLI Reference.

  • Enable Advanced URL Defense. For details, see Enabling or disabling advanced URL defense.