Policy Configuration : Configuring Security Services Settings

Email Filtering
During an outbreak, Email filtering allows for preemptive blocking of known filenames and newly discovered viruses before the Anti-Virus signature (DAT) files are actually available.
This feature also provides full filename blocking of virus files, allowing SonicWALL to block only malicious attachments, while enabling all other attachments through. For example, during a virus outbreak, only the virus file is blocked while other productive files (such as Word documents and Excel spreadsheets) are allowed through.
To configure email filter settings for one or more SonicWALL appliances, follow these steps:
1
2
Expand the Security Services tree and click EMail Filter. The EMail Filter screen displays.
 
Email Attachment Filtering
This section allows the administrator to specify file extensions to filter. By default, common executable files.vbs and .exe are blocked.
To enable infected email attachment blocking on inbound SMTP and POP3 Email protocols, select Enable Email Attachment Filtering Alert Service. Only files that were discovered to be infected are blocked. If a message contains uninfected attachments, those are forwarded to the recipient.
To specify file extensions to filter, select Enable Email Attachment FIltering of Forbidden File Extensions.
If choosing to specify forbidden file extensions, enter the file extensions (one at a time) in the Forbidden File Extensions field and click Add. Remove extensions from the list by selecting the check box to the left of the file extension and clicking Update at the bottom of the page.
Click Update to save your changes.
Email Attachment Filtering Options
This section allows the administrator to handle forbidden file extensions in the following two ways:
Select Disable the forbidden file by altering the file extension and attach warning text to alter the file extension by replacing the third character of file extensions with “_”. If the email attachment is a valid file, the message recipient might return the attachment to its original file extension without damaging the file.
Select Delete forbidden file and attach warning text to remove the forbidden file from the Email message entirely and attach warning text to the message.
In the Warning Message Text field (maximum 256 characters), enter the text you wish to attach to messages containing forbidden files.
Click Update to save your changes.
Email Blocking
This option allows the administrator to block fragments of Email messages.
Check the Block Email fragments (Content-Type message\partial) to block fragmented messages from being delivered.
Click Update to save your changes.
When you are finished, click Update. The settings are changed for each selected SonicWALL appliance. To clear all screen settings and start over, click Reset.
The SonicWALL appliance blocks viruses that are discovered by the virus signature files and filenames that are known to be infected during an outbreak.