02-15-2015 09:22 PM
i got mail from my printer authorized agent (both are private mail ID's). but it has blocked due to that mail contains virus, blocked via Cisco appliance. how it has happened? which one is that appliance? kindly answer it, i am very eager to know.
02-15-2015 10:03 PM
Hello,
If you could review the message tracking logs on your ESA device.
GUI > Monitor > Message Tracking
Search and locate, then click on 'show details'
It will show you what type of viral definition was seen within the attachment and by which Virus scanner (if the ESA dropped it).
Or if you have content filters scanning to drop it.
Please review this and let us know if you have further questions.
You'll see something similar to:
---
Wed Feb 4 14:08:49 2015 Info: MID 144 interim AV verdict using Sophos VIRAL
Wed Feb 4 14:08:49 2015 Info: MID 144 antivirus positive 'Troj/Agent-AIRO'
Wed Feb 4 14:08:49 2015 Info: Message aborted MID 144 Dropped by antivirus
---
02-15-2015 10:17 PM
sorry, i do not have device to view and show. i am a end user. and mail having the attachments. so i need to know, what is the appliance that to block? and how?
02-15-2015 10:19 PM
I'm afraid we cannot determine what may have caused the block of the email then.
If it was due to local content filters in place, or if the email contained something of spammy nature (false positive if it's a legitimate email) or if the attachment contained a virus.
These are the three aspects i believe that can block it, but without the tracking information we cannot determine this and can only assume one of the three scenarios.
Did you get any bounce replies to the email or did the private ID's receive any bounce replies if the ESA blocked it?
02-15-2015 10:24 PM
which appliance is that to block email contains virus?
02-15-2015 10:29 PM
If your client or the domain is using a Cisco ESA device.
THey would have purchased either Sophos or McAfee license key for virus filtering.
02-15-2015 10:37 PM
thank you, i will investigate it to my colleague. once again thank you.
how do we block facebook.com and youtube.com on cisco router 1941 ?
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: