analysis riskware policy fe-rules block

Prev Next

Globally enables or disables the blocking of emails marked as riskware based on the set of Trellix common rules on the EX Series appliance only.

The appliance blocks the email from being delivered to the intended recipient and marks the email for quarantine. When Trellix rules for blocking email based on riskware detection are disabled, the EX Series appliance will process the email for analysis. If riskware is detected, an alert notification is sent but the email will not be blocked.

When emails are blocked based on riskware detection, you can view the analysis results on the eQuarantine page of the Web UI.

The blocking of emails based on Trellix rules for riskware detection is disabled by default.

Note

This command replaces the deprecated analysis riskware policy block command introduced in Release 8.0.

Syntax

[no] analysis riskware policy fe-rules block

Parameters

no

Use the no form of this command to disable the blocking of email when marked as riskware based on Trellix rules for the EX Series appliance.

Example

The following example enables Trellix rules to block emails based on riskware detection:

hostname (config) # analysis riskware policy fe-rules block

The following example disables Trellix rules to block emails based on riskware detection:

hostname (config) # no analysis riskware policy fe-rules block

User role

Admin or Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Email Security — Server: Release 8.4.1