Configures the block policy rule based on the MD5 checksum attachment.
No further analysis is performed on the MD5 checksum attachment. All the recipients will receive a copy of the original malicious email with a different subject. In the Email Security — Server Web UI, an email can either be deleted or released from the eQuarantine page.
Files matching the block policy rule for the MD5 checksum is case-sensitive.
Note
When you remove the rule based on the MD5 checksum attachment from a blocked list, files matching that rule are automatically marked as malicious without analysis. You can specify how long to retain the last analyzed attachment with the same MD5 checksum by using the
blacklist files auto past_hourscommand. The default time to retain the files is four hours.
For details about how to configure a blocked list, refer to the "Rule Configuration on Allowed and Blocked Lists" chapter of the Email Security — Server User Guide.
Syntax
[no] email-analysis blocked-list md5sum <MD5_checksum_attachment>
Parameters
no
Deletes the block policy rule based on the MD5 checksum attachment.
<MD5_checksum_attachment>
MD5 checksum attachment of the block policy rule.
Examples
The following example adds the MD5 checksum attachment to a blocked list:
hostname (config) # email-analysis blocked-list md5sum d41d8cd98f00b204e9800998ecf8427e
The following example deletes the MD5 checksum attachment from a blocked list:
hostname (config) # no email-analysis blocked-list md5sum d41d8cd98f00b204e9800998ecf8427e
User role
Admin or Operator
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Email Security — Server: Release 7.6