This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Blocking Unscannable and Encrypted files on your Sophos SG UTM

Hi all,

We recieved an email from Sophos advising us to turn on the following security features which we have done.

Email Protection SMTP -> Malware scanning: "Quarentine unscannable and encrypted content"

Email Protection -> POP3 -> Malware -> Malware scanning: "Quarantine unscannable and encrypted content"

Web Protection -> Filtering Options -> Misc -> "Block unscannable and encrypted files"

 

We have created a whitelist allowing users and known safe external bodies to send and recieve emails with password protected attachements which is working well.

If internal users send emails outbound with password protected attachments they recieve an email from UTM informing them that this mail has been quarentined and to speak with IT.

However, if an external entitiy sends an email with a password protected attachment inbound neither the sender or recipient recieve any notification that the email is quarentined.

Is there a way to enable this behaviour because obviously with no notification neither party know there has been an issue.

 

Currently we have to constantly check the mail manager to see if such emails have been sent otherwise either the sender or recipient has to realise there has been an isseue and contact us. This is not good.



This thread was automatically locked due to age.
Parents
  • Hi  

    When an external user sends an Email with a password-protected attachment, it will be accepted and then moved to the Quarantine list by UTM. In this case, the sending mail server will not see anything as the UTM accepts the mail and ends the SMTP connection with 250 OK message (followed by QUIT 221). 

    However, when an Internal user sends an Email, it's still within the premises and has not been transacted with the recipient server. Hence, UTM will send an Email regarding Email being quarantined.

    Regards

    Jaydeep

Reply
  • Hi  

    When an external user sends an Email with a password-protected attachment, it will be accepted and then moved to the Quarantine list by UTM. In this case, the sending mail server will not see anything as the UTM accepts the mail and ends the SMTP connection with 250 OK message (followed by QUIT 221). 

    However, when an Internal user sends an Email, it's still within the premises and has not been transacted with the recipient server. Hence, UTM will send an Email regarding Email being quarantined.

    Regards

    Jaydeep

Children
No Data