<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mail attachment virus scanning in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11894#M8742</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bringing back an old thread:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We had some cryptolocker recently. Mail containting a zip.&lt;/P&gt;&lt;P&gt;although the antivirus definitions know of the specific variant, the firewall will not block them in SMTP traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What are the limits for STMP attachment scanning regarding to compressed files ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Mar 2015 10:37:14 GMT</pubDate>
    <dc:creator>dieter_b</dc:creator>
    <dc:date>2015-03-16T10:37:14Z</dc:date>
    <item>
      <title>Mail attachment virus scanning</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11884#M8732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How can I implement proper mail attachment virus scanning ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For incoming mail, I have an antivirus security profile in place that should block virusses (smtp decoder), nothing fancy really:&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="7132" alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/7132_pastedImage_1.png" style="width: 808px; height: 521px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I notice that the PA doesn't filter attached virusses too well. Luckily (as is best practice) I have several layers of antivirus protection for mail:&lt;/P&gt;&lt;P&gt;external spam filter --- firewall --- (spamfilter in DMZ; spam only) --- antivirus on internal mailserver --- endpoint antivirus + Outlook attachment filter&lt;/P&gt;&lt;P&gt;So virus infected mails usually don't reach the user. However, I think it's better that they are identified and blocked at an early stage, which is not the case now. The firewall plays an important role here, I feel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I feel like PA antivirus doesn't do smtp antivirus very well. E.g. none of the test virus/spam mails from &lt;A href="http://www.emailsecuritycheck.net/" title="http://www.emailsecuritycheck.net/"&gt;Free Email Security Check&lt;/A&gt; were blocked by the PA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What can I do to improve on this ? Or is PA just not up to the task ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jun 2013 09:06:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11884#M8732</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-06-27T09:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: Mail attachment virus scanning</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11885#M8733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi dieterb,&lt;/P&gt;&lt;P&gt;I was wondering whether the PANFW isn't screening the mails for the attachments at all. Can you show us the screenshot of the security rule where this profile has been configured under. &lt;/P&gt;&lt;P&gt;The link below also describes the best practices for Threat Prevention&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-3094"&gt;https://live.paloaltonetworks.com/docs/DOC-3094&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The pages 19 through 22 explain about how to configure the anitvirus feature.&lt;/P&gt;&lt;P&gt;I suggest taking a look at these settings as well mentioned under this document.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and best regards,&lt;/P&gt;&lt;P&gt;Karthik RP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jun 2013 13:52:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11885#M8733</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-06-27T13:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: Mail attachment virus scanning</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11886#M8734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nothing fancy in the rule:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/7140_pastedImage_0.png" style="width: 1098px; height: 31px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="7135" alt="" class="jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/7135_pastedImage_1.png" style="width: 705px; height: 429px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've browsed through the pages you suggested (haven't had time yet to review the entire document), but nothing obvious that suggests my config is wrong...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: Dieter Bulcke&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jun 2013 15:43:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11886#M8734</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-06-27T15:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: Mail attachment virus scanning</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11887#M8735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can the message format the SMTP mail is presented to us be a reason the PA doesn't "see" the attachments ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jun 2013 06:28:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11887#M8735</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-06-28T06:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: Mail attachment virus scanning</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11888#M8736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;AV scanning for the Email attachments is supported.&lt;/P&gt;&lt;P&gt;If the SMTP connection is over SSL ,you&amp;nbsp; need to implement SSL-Decryption on the PAN-OS firewall to scan the clear-text&amp;nbsp; traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jun 2013 09:41:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11888#M8736</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-06-28T09:41:59Z</dc:date>
    </item>
    <item>
      <title>Re: Mail attachment virus scanning</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11889#M8737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Plain standard unencrypted SMTP, so no decryption necessary for content inspection.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jun 2013 09:53:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11889#M8737</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-06-28T09:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Mail attachment virus scanning</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11890#M8738</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Make sure the firewall is installed with latest Antivirus version -1046-1457.&lt;/P&gt;&lt;P&gt;If the traffic logs show Email traffic matching the security rule &lt;STRONG&gt;Allow-In_Mail&lt;/STRONG&gt; and no Threat logs are generated ,open a case with Support.&lt;/P&gt;&lt;P&gt;#As an additional step, you can associate a&amp;nbsp; File-Blocking profile with this rule and monitor the Wildfire logs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jun 2013 10:21:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11890#M8738</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-06-28T10:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: Mail attachment virus scanning</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11891#M8739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It didn't update to the latest antivirus yet, but that should not be the issue, right ? Virusses in other traffic is detected fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I checked earlier, incoming mail passes the right rule.&lt;/P&gt;&lt;P&gt;No wildfire subscription.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll open (yet another, almost weekly now) ticket with support.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jun 2013 10:49:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11891#M8739</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-06-28T10:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: Mail attachment virus scanning</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11892#M8740</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am using SMTP connection over SSL.&lt;/P&gt;&lt;P&gt;How can I implement SSL Decryption&amp;nbsp; for SMTP?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Aug 2014 09:53:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11892#M8740</guid>
      <dc:creator>NashTechIT</dc:creator>
      <dc:date>2014-08-29T09:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: Mail attachment virus scanning</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11893#M8741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The below document could be helpful :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1412"&gt;How to Implement SSL Decryption&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Aug 2014 22:31:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11893#M8741</guid>
      <dc:creator>tshiv</dc:creator>
      <dc:date>2014-08-29T22:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: Mail attachment virus scanning</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11894#M8742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bringing back an old thread:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We had some cryptolocker recently. Mail containting a zip.&lt;/P&gt;&lt;P&gt;although the antivirus definitions know of the specific variant, the firewall will not block them in SMTP traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What are the limits for STMP attachment scanning regarding to compressed files ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Mar 2015 10:37:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mail-attachment-virus-scanning/m-p/11894#M8742</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2015-03-16T10:37:14Z</dc:date>
    </item>
  </channel>
</rss>

