Skip to main content
CAD
New Member
February 19, 2016
Question

Block attachment .zip that content Virus

  • February 19, 2016
  • 4 replies
  • 9582 views

Hello,

 i want to block any attachment (.zip ) content virus, but pass clean .zip 

is there any possibility?

 

thanks 

 

 

    4 replies

    seadave
    New Member
    February 21, 2016

    The FN will do this.  What device and FW are you running?  You need to take some things into consideration:

     

    [ol]
  • For this to be effective you need to enable SSL deep inspection as most viruses like this will come via email or users' personal gmail/hotmail/yahoo account which will be encrypted.  More email is being delivered via TLS also.  If the policy doesn't decrypt (deep-scan) the connection, the ZIP will pass through.
  • You need to watch out for MS Office files with Macros.  The are increasingly a problem.  We use Mimecast to filter these out in the cloud.  Many ZIP payloads will have a file such as this which will appear clean unless there is a specific signature for it.  It will be downloaded and if the user opens, and if they don't have the proper MS Office macro protection enabled, the document will run a script that attempts to download a payload from the web.  Having proper EXECUTABLE DLP rules in place can help mitigate this risk.  In otherwords, users are NOT allowed to download EXEs, COMs, DLLs, TAR, etc from sites other than those on a trusted list.  It takes extra work to get this setup, but we have used this model for years and it has kept us clean.
  • Test your rules by using www.eicar.com: http://www.eicar.org/85-0-Download.html These are NOT actual viruses, but test signatures that all quality virus scanners should detect to let you know your system is working.  What makes this helpful is that these links are offered via HTTP and HTTPS connections, RAW and ZIP'd, so you can see if a file that is ZIP'd is passed through.  This would indicate you need to revisit how you have your filtering configured.[/ol]
  • CAD
    CADAuthor
    New Member
    February 21, 2016

    Thanks for reply,

    The Deep-inspection Already Enable for the policy. and test Eicar virus it blocked successfully 

     

    but can you explain me Macro files i dont understand , other word can you help me to block this files.

     

    thanks

    CAD
    CADAuthor
    New Member
    February 21, 2016

    Sorry i forgot to tell my device model,

    i am using Fortigate200D and FW(5.2.3)

     

    thanks.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.