Enables or disables blocking emails based on riskware detection custom policy rules on the EX Series appliance.
When a matched policy rule is enabled to block an email based on riskware detection on the EX Series appliance, traffic matching the submission is marked as riskware and it will be included for further analysis. The EX Series appliance blocks the email from being delivered to the intended recipient and marks the email for quarantine. When a matched policy rule is disabled to not block an email based on riskware detection, traffic matching the submission is marked as custom riskware. When a matched policy rules is enabled to block an email on riskware detection, traffic matching the submission is marked as custom riskware blocked.
After you have configured the EX Series appliance to detect matched custom policy rules from emails that are blocked based on riskware detection, you can view the analysis results on the eAlerts > Alerts page in the Web UI. Blocked email can be viewed on the eQuarantine page in the Web UI.
The blocking emails based on riskware detection custom policy rules feature is disabled by default.
Syntax
[no] analysis riskware policy rule <rule_ID> block
Parameters
no
Use the no form of this command to disable a particular custom policy rule ID.
<rule_ID>
A particular policy rule ID.
Example
The following example enables a custom policy rule ID to block an email based on riskware detection:
hostname (config) # analysis riskware policy rule 65000 block
The following example disables a custom policy rule ID to not block an email based on riskware detection:
hostname (config) # no analysis riskware policy rule 65001 block
User role
Admin or Operator
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Email Security — Server: Release 8.0.1