This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

UTM email proxy AV capabilities

Hi Guys,
we are using the UTM in the newest version and beside other stuff the MDaemon email server. (Basically a cheap exchange)
It has a built-in antivirus, which is only so-so.
So for now, we are catching the emails from the provide and parse them into the user folders. This is done as a normal "internet-traffic".
While we are about to move the MDaemon to a W2016 server (re-install), we are planning to set our server itself as the MX.
For sure we will use the Sophos UTM as the "man-in-the-middle" via the SMTP proxy. I've seen that it has an built-in AV as well.
While the MDaemon AV is rather stupid, not even able to scan RAR files (which are always quarantined) or lots of other rather common formats, we think about not using it's AV anymore.
In exchange, we would like to rely (not as a sole AV!) for email AV onto the UTM.
So two questions:
1. Which file-formats can be scanned? RAR, TAR, 7Zip and others as well?
2. Is the AV "good" enough to shut down the so-so one from our email server?
(We also use the cloud based endpoint protection from Sophos as an AV for the computers)
Regards,
Matthias
 


This thread was automatically locked due to age.
  • Hallo Matthias,

    I would say "Yes" and "No" to your question as it really depends on what you configure.  No AV will be able to look inside an encrypted attachment, so you will probably want to have the SMTP Proxy quarantine Unscannable emails.

    Is this a question about the Sophos UTM Manager or strictly about the SMTP Proxy in the UTM?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Thanks Bob!

    It's not about encrypted ones! Its just that the MDaemon is not smart enough to scan anything else other than ZIP.
    It's just about the UTM Proxy, not the manager.
    Sure we are quarantining the non-scannable files. But the Major question was it there will be apart from encrypted much more of these.
    Regards,
    Matthias