Use the commands in this procedure to enable or disable Trellix and custom YARA rules on your Email Security - Server appliance. You cannot use the Web UI to configure YARA rules.
Prerequisites
An established connection between the Email Security - Server appliance and the Internet.
Administrator or Operator access to the Email Security - Server appliance.
To enable Trellix and custom YARA rules:
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Enable Trellix and custom YARA rules.
hostname (config) # yara policy both
Verify your configuration.
hostname (config) # show static-analysis config ..... Yara Configuration Yara policy : both .....
Save your changes.
hostname (config) # write memory
To disable Trellix and custom YARA rules:
Go to CLI configuration mode.
hostname > enable hostname # configure terminal
Disable Trellix and custom YARA rules.
hostname (config) # yara policy disable
Verify your configuration.
hostname (config) # show static-analysis config ..... Yara Configuration Yara policy : disable
Save your changes.
hostname (config) # write memory