Hello guys,
in the data sheet from FortiMail there is mention about attachment inspection inside of email
https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/FortiMail.pdf
But in the logs from FortiMail forwarded from appliance to our logserver i do not see full smtp headers listed - there are some basic - to,from,mail-id etc. but i specifically looking for Content-type/Content-disposition headers to be able to see if the email contains attachment or not. From what i checked FM only have rules to inspect particullar behaviour based on db signatures but this simple information is slipping somewhere - is FM able to provide this simple metadata?
Appreciated your support
#FortiMail #FortiGa
Hi
In the content profile, for each action in the Attachment Scan Rules, you can edit the action and insert the any custom header you want.
You can do the same in AV profile as well if needed.
Hope it helps.
Hi,
we are talking about FM or FG? Do you have screenshot?
thanks
I mean FortiMail
Thanks, ill check.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.