bottracker file-inspect enable

Prev Next

Enables the file inspection feature, which allows the Network Security appliance to inspect files that are detected in network traffic.

When file inspection is enabled, files are compared to a denylist. If a file matches the denylist, it is marked as malicious. The malicious traffic is blocked and an alert is created. File inspection can match on IP addresses, URIs, domains, and streaming sessions as well as other files. Inspection of hash files can be enabled separately.

Important

The file inspection feature is not supported on Trellix NX 10000 models.

Caution

Enabling file inspection may impact performance, especially latency, on the Network Security appliances working in inline mode. The impact can vary depending on the capacity of the appliance and the volume of file traffic processed by the appliance. Under certain conditions, if an appliance receives at least 25 percent file traffic volume and operates at 50 percent of peak throughput, the latency can increase up to 1.5 to 2 times normal.

Syntax

[no] bottracker file-inspect enable

Parameters

[no]

Use the no form of this command to disable file inspection.

Example

The following example enables the file inspection feature on the Network Security appliance.

hostname (config) # bottracker file-inspect enable

The following example disables the file inspection feature.

hostname (config) # no bottracker file-inspect enable

User role

Admin or Operator

Command mode

Config

Supported appliances

  • Network Security: Release 8.3.5