Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ede_pfau
SuperUser
SuperUser

AV blocks " encrypted archive"

hello all, I keep getting these messages (alert emails) like this one from a FGT running 4.3.15:
Message meets Alert condition File Block Detected: " A56489778.pdf" Protocol: " imaps" Source IP: 192.168.16.10 Destination IP: 81.81.81.81 Email Address From: " valid@tld.de" Email Address To: " recipient@bla.de" date=2014-03-11 time=20:36:25 devname=blob device_id=FGT80C3000000000 log_id=0262008962 type=virus subtype=scanerror pri=warning vd=" root" msg=" Encrypted archive." status=" blocked" service=" imaps" src=192.168.16.10 dst=81.81.81.81 sport=51429 src_port=51429 dport=993 dst_port=993 src_int=" dmz" dst_int=" wan1" policyid=30 identidx=0 serial=4358147 dir=N/A file=" A56489778.pdf" checksum=" N/A" quarskip=" No skip" virus=" N/A" dtype=" N/A" ref=" N/A" url=" N/A" carrier_ep=" N/A" profile=" scan_secalso" profiletype=" Antivirus_Profile" profilegroup=" N/A" user=" N/A" group=" N/A" agent=" N/A" from=" valid@tld.de" to=" recipient@bla.de"
If haven' t heard back yet if that mail really was blocked but the message says so. Can anybody please help me understand which setting is causing this and whether mails are REALLY blocked?

Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
6 REPLIES 6
netmin
Contributor II

My best guess is: config antivirus profile edit scan_secalso config imaps set archive-block encrypted Per fundamentals guide: in proxy inspection mode the attachment should be removed (replacement message added) but the mail was forwarded to the recipient.
ede_pfau
SuperUser
SuperUser

hello netmin, thanks for posting. Unfortunately, my config holds ' unset archive-block' so that no ' special' undecodeable archive get blocked. Puzzled.

Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
netmin
Contributor II

Hmmm ... dlp sensor replaced antivirus file-filter ... any chance there is a dlp sensor / rule using ' always' or ' encrypted' field and triggering on *.pdf pattern or ' unknown' file-type? No other idea...
Sean_Toomey_FTNT

Ede, I am stumped as well, barring any config on the DLP sensor. You might be better off opening a TAC case on this one so they have the benefit of your full config, along with a diag debug report / exe tac report. Cheers!
-- Sean Toomey, CISSP FCNSP Consulting Security Engineer (CSE) FORTINET— High Performance Network Security
abc987
New Contributor II

Hi Ede, did you find any solution to get out of this problems?

FCNSP/WCSP

FCNSP/WCSP
ede_pfau
SuperUser
SuperUser

No, sorry I have no idea why but these log entries vanished over night...


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors