09-28-2016 12:40 PM
Our Ironport uses Sophos. Recently Sophos classified something as Unscannable and quarantined it (as per policy). VIP user is upset that his mail is getting blocked. I am not going to turn off AV for this rare occurrence.
I know how to report false positives for SPAM & HAM, but how do i report this?
We do not have a direct relationship with Sophos. Submitting on their site asks for the OS used, but there is no option that I can see for AsyncOS.
Any advice?
Thanks
09-28-2016 01:10 PM
Hello,
Cisco handles the communication with Sophos for any false-negative/false-positive submissions. If you do truly need to submit a file for false-negative/false-positive analysis, please go ahead and open up a TAC case and we'll be sure to take care of it for you.
However, it sounds like you may just need to adjust your mail policy since it's actually reading as 'Unscannable' and not Virus Positive. You can perform this via Mail Policies --> Incoming/Outgoing Mail Policies --> Anti-Virus --> Unscannable Messages.
Thanks!
-Dennis M.
09-28-2016 01:11 PM
Hi Greg,
Attachments that are marked as unscannable by sophos are accompanied by an error code.
http://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/117849-qanda-esa-00.html
The above article provides reasons for some of the error codes, it usually is due to the type or composition of the attachment itself.
To get a detailed analysis you would need to open a TAC case with a copy of the attachment in question.
Thanks
Libin
09-29-2016 01:44 AM
The same VIP would no doubt want your hide if you or your ESA let an item of encrypting ransomware in. Other options for dealing with this type of mail might be:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide