Enabling or disabling riskware detection policy rules

Prev Next

You can enable or disable riskware detection policy rules by using the Email Security - Server appliance Web UI or CLI:

When you enable a particular policy rule based on riskware detection on the appliance, traffic matching the submission is marked as custom riskware and it will be excluded from further analysis. When you disable a particular policy rule based on riskware detection, traffic matching the submission is not marked as custom riskware. After you have configured the Email Security - Server appliance to detect a riskware policy rule, you can view the analysis results on the eAlerts > Riskware page in the Web UI. For details about how to view the matched riskware alerts, see Viewing riskware alert details in the Web UI.

Prerequisites

  • Administrator or Operator access to the Email Security - Server appliance

  • An established connection to the Internet

  • A connection to the DTI Cloud

  • Download and install the latest security content with new riskware policy rules by using the fenet security-content apply-update command, For details about how to update security content, refer to the System Administration Guide.