Symantec 10490452 Administration Guide - Page 84

Determining your suspicious attachment policy, Changing default virus actions, Add Action

Page 84 highlights

84 Configuring email filtering Creating virus, spam, and compliance filter policies If a message is unscannable A message can be unscannable for viruses for a variety for viruses of reasons. For example, if it exceeds the maximum file size or maximum scan depth configured on the Scanning Settings page, or if it contains malformed MIME attachments, it may be unscannable. Compound messages such as zip files that contain many levels may exceed the maximum scan depth. If a message contains an encrypted attachment The message contains an attachment that cannot be scanned because it is encrypted. If a message contains a suspicious attachment The message contains an attachment that, according to Symantec filters, may contain a virus or other threat. If a message contains spyware or adware The message contains spyware or adware. 7 Select the desired action. See Table 4-2, "Filtering actions by verdict," on page 64. For some actions you need to specify additional information in fields that appear below the action. 8 Click Add Action. 9 If desired, add more actions. See Table 4-3, "Compatibility of filtering actions by verdict," on page 68. 10 Click Save. Determining your suspicious attachment policy When you choose the condition, "If a message contains a suspicious attachment," two additional actions become available: ■ Delay message delivery ■ Strip and hold in Suspect Virus Quarantine Both of these actions enable you to make use of the Suspect Virus Quarantine to delay filtering these messages until a later time, when updated virus definitions may be available. This provides enhanced protection against new and emerging virus threats. By default, these messages are held in the Suspect Virus Quarantine for 6 hours. You can vary the number of hours on the Settings > Quarantine page, Virus tab. Changing default virus actions By default, inbound and outbound messages containing a virus or mass-mailing worm, and unscannable messages, including malformed MIME messages, will be

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258

84
Configuring email filtering
Creating virus, spam, and compliance filter policies
7
Select the desired action.
See
Table 4-2, “Filtering actions by verdict,”
on page 64.
For some actions
you need to specify additional information in fields that appear below the
action.
8
Click
Add Action
.
9
If desired, add more actions.
See
Table 4-3, “Compatibility of filtering actions by verdict,”
on page 68.
10
Click
Save
.
Determining your suspicious attachment policy
When you choose the condition, “If a message contains a suspicious
attachment,” two additional actions become available:
Delay message delivery
Strip and hold in Suspect Virus Quarantine
Both of these actions enable you to make use of the Suspect Virus Quarantine to
delay filtering these messages until a later time, when updated virus definitions
may be available. This provides enhanced protection against new and emerging
virus threats.
By default, these messages are held in the Suspect Virus Quarantine for 6 hours.
You can vary the number of hours on the Settings > Quarantine page, Virus tab.
Changing default virus actions
By default, inbound and outbound messages containing a virus or mass-mailing
worm, and unscannable messages, including malformed MIME messages, will be
If a message is unscannable
for viruses
A message can be unscannable for viruses for a variety
of reasons. For example, if it exceeds the maximum file
size or maximum scan depth configured on the
Scanning Settings page, or if it contains malformed
MIME attachments, it may be unscannable. Compound
messages such as zip files that contain many levels may
exceed the maximum scan depth.
If a message contains an
encrypted attachment
The message contains an attachment that cannot be
scanned because it is encrypted.
If a message contains a
suspicious attachment
The message contains an attachment that, according to
Symantec filters, may contain a virus or other threat.
If a message contains
spyware or adware
The message contains spyware or adware.