Enables controlled live mode. In controlled live mode, the Email Security — Server appliance monitors and manages communication between the Internet and the suspicious binary under analysis. MVX sends and receives this traffic on pether2. Operating in controlled live mode enables the appliance to detect malware that requires remote objects.
Controlled live mode is disabled by default. You enable the feature separately from configuring the feature settings.
Important
Validate end-to-end connectivity before you enable controlled live mode or URL dynamic analysis. To perform this validation using the CLI, use the
analysis live check‑connectioncommand in configuration mode.
Controlled live mode requires pether2 network configuration settings:
pether2 IPv4 address and mask length
Default gateway IPv4 address
DNS name server IPv4 address
If the local network uses a proxy server to access the Internet, additional configuration settings are required:
Proxy server IPv4 address and port number
Proxy server credentials (if authentication is required)
Syntax
[no] email-analysis controlled-live-mode enable
Parameters
no
Disables multistage exploit detection.
Examples
The following example enables multistage exploit detection:
hostname (config) # email-analysis controlled-live-mode enable
The following example disables multistage exploit detection:
hostname (config) # no email-analysis controlled-live-mode enable
User role
Admin
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Email Security — Server: Release 7.8