This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Attachment Filter

Hi all,

I receive product feature or setting inquiring regarding sophos email appliance.

customer inquiring if sophos email appliance have setting or features like MIME Sweeper Attachment Filtering.

Whereby every email from outbound with attachment will be quarantine and email will be deliver to enduser with banner to contact IT for attachment release.

I have check email appliance setting and the setting can be configured except email that deliver to end user contain only banner and header, Can someone help me or have any information reagrding this setting?. Thanks

:18927


This thread was automatically locked due to age.
Parents
  • Hi Azwan,

    It should be possible to set this up.  In fact, we have a default rule which does this automatically for you.  Take a look at:

    'Configuration > Policy > Anti-Virus > SophosLabs Suspect Attachments to all'

    This won't remove every attachment, but will remove any attachments that are identified by SophosLabs as suspicious/infectable.

    Alternatively, you can setup your own rules to remove attachments.  When creating the rule you need to select 'Quarantine, drop file(s) and continue' on the Main Action tab.  The user will still receive the message, but the attachment will be removed.  You can then use the 'Additional actions' tab to also add a banner to the message. 

    In both cases, the complete message (including attachments) could still be released from quarantine by an Administrator.

    Hope this helps - let me know if you have any questions.

    Tom.

    :18959
Reply
  • Hi Azwan,

    It should be possible to set this up.  In fact, we have a default rule which does this automatically for you.  Take a look at:

    'Configuration > Policy > Anti-Virus > SophosLabs Suspect Attachments to all'

    This won't remove every attachment, but will remove any attachments that are identified by SophosLabs as suspicious/infectable.

    Alternatively, you can setup your own rules to remove attachments.  When creating the rule you need to select 'Quarantine, drop file(s) and continue' on the Main Action tab.  The user will still receive the message, but the attachment will be removed.  You can then use the 'Additional actions' tab to also add a banner to the message. 

    In both cases, the complete message (including attachments) could still be released from quarantine by an Administrator.

    Hope this helps - let me know if you have any questions.

    Tom.

    :18959
Children
No Data