email-analysis adv-url-defense rewrite enable

Prev Next

To enable or disable rewriting URLs based on the Advanced URL Defense analysis, use the email-analysis adv-url-defense rewrite enable command in configuration mode.

When the Email Security — Server appliance is deployed in block mode, you can enable the Email Security — Server appliance to rewrite one or more URLs within a message. One email can contain one or more suspicious URLs. The URLs that match the heuristic rules are sent back to the DTI Cloud for further analysis. The Email Security — Server appliance prepends protect.fireeye.com to the rewritten URL in the following example:

https://protect.fireeye.com/url?k=df35d163-2d4a-45fb-8df2-62d3517eae72&u=http://protection-update.team.com1serv13.webs001cr-cm-l0gin-submit-id.app1-lo0gin-submit-id.pp1-login-login-2014.ap.serv64.idmsa-protection.com

URLs are rewritten only if they are detected as new or in the process of being analyzed by the Trellix Advanced URL Defense Detection Engine. If the URL is detected as malicious, you are redirected to a block page to inform you that the site contains malicious content. If the URL is detected as suspicious, you are redirected to a warning page to inform you that the site might contain malicious content. If the URL is detected as nonmalicious, you can access the original URL in the email message.

Caution

You must enable rewriting URLs when the Email Security — Server appliance is deployed in block mode and Advanced URL Defense is enabled. If you do not enable rewriting URLs, emails containing a URL will be delivered to you with the links intact. If a verdict is returned later from the Trellix Advanced URL Defense Detection Engine that the email is malicious, your system will not be protected if you click on the link.

Use the show email-analysis adv-url defense configuration command to verify that rewriting URLs is enabled.

Syntax

no

email-analysis adv-url-defense rewrite enable

Parameters

no

Disables rewriting URLs based on the Advanced URL Defense analysis.

Examples

The following example enables rewriting URLs based on the Advanced URL Defense analysis:

hostname (config) # email-analysis adv-url-defense rewrite enable

The following example disables rewriting URLs based on the Advanced URL Defense analysis:

hostname (config) # no email-analysis adv-url-defense rewrite enable

User role

Admin or Operator

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Email Security — Server: Release 7.6.0