Enables the file inspection feature for script files, which allows the Network Security appliance to inspect the script files that are detected in network traffic.
When file inspection is enabled, the script files are compared to a denylist. If a script file matches any file from the denylist, it is marked as malicious. The malicious traffic is blocked and an alert is created. File inspection can match on IP addresses, URIs, domains, and streaming sessions as well as other files. Inspection of hash files can be enabled separately.
Important
The file inspection feature is not supported on Trellix NX 10000 models.
Caution
Enabling file inspection may impact performance, especially latency, on the Network Security appliances working in inline mode. The impact can vary depending on the capacity of the appliance and the volume of file traffic processed by the appliance. Under certain conditions, if an appliance receives at least 25 percent file traffic volume and operates at 50 percent of peak throughput, the latency can increase up to 1.5 to 2 times normal.
Syntax
[no] bottracker file-inspect script-file enable
Use the ‘no’ form of the command to disable inspection of script files.
Parameters
[no]
Use the no form of this command to disable file inspection.
Example
The following example enables inspection of script files.
hostname (config) # bottracker file-inspect script-file enable hostname (config) #
User role
Administrator or operator
Command mode
Configuration
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Network Security: Release 10.0.2