Analyzing files tab
Transferring files
Partial download | When a download is incomplete, for example, due to a connection failure during a file download via HTTP, the user can continue to download from where the error occurred, instead of having to download the whole file again. This is called a partial download – the download does not correspond to a whole file. The option Partial download defines how the firewall’s HTTP proxy reacts to such downloads.
|
File size limit [0-2147483647(KB)] | When files downloaded off the internet via HTTP get too huge, they can affect internet bandwidth for quite a long stretch of time. To avoid this situation, indicate the maximum size (in KB) that can be downloaded via HTTP. |
URLs excluded from the antivirus scan | A URL category or category group can be excluded from the antivirus scan. By default, there is a URL group named antivirus_bypass in the object database containing Microsoft update sites. |
File filter (MIME type)
Status | Indicates whether a file is active or inactive. Two statuses are available: “Enabled” or “Disabled”. |
Action | Indicates the action to be taken for the file in question, out of three possibilities:
|
MIME type | Indicates the file content type. This could be text, an image or a video, to be defined in this field. EXAMPLES |
Maximum size for antivirus scan and sandboxing (KB) |
This option corresponds to the maximum size of files that will be scanned.
|
Actions on files
When a virus is detected | This field contains two options. By selecting “Block”, the analyzed file will not be sent. By selecting “Pass”, the antivirus will send the file in its original form. |
When the antivirus scan fails | This option defines the behavior of the antivirus module if the analysis of the file it is scanning fails. EXAMPLE If Block is specified, the file being scanned will not be sent. If Pass without analyzing has been specified, the file being scanned will be sent. |
When data collection fails | This option defines the behavior of the antivirus module when certain events occur. It is possible to Block traffic when information retrieval fails, or Pass without analyzing. EXAMPLE |