Enable File Inspection
To inspect files for threats, enable the file inspection features in a web profile, then assign the web profile to an internet access rule.
File Inspection uses multiple features to evaluate for malicious files. For details, see Manage File Inspection and Analysis.
Once inspections are complete, a file is either delivered to the end user or the connection is terminated and the user is shown a block page.
Once you have enabled File Inspection, to monitor and review Umbrella's inspection activities, use the Security Activity and Activity Search reports.
Table of Contents
Prerequisites
- Full Admin user role. For more information, see Manage Accounts.
- Determine which options you want to enable. For details, see Manage File Inspection.
If you will enable file analysis: Before you enable that feature, see important caveats in Enable File Analysis by Secure Malware Analytics.
By default, File Inspection is enabled and file analysis is not.
You must first enable File Inspection before you can enable file analysis. - Certificates are required to decrypt traffic and detect files, and to display block notifications. For more information, see Certificates for Internet Decryption.
Procedure
- Navigate to Secure > Profiles > Security Profiles.
- Click +Add or expand an existing web profile.
- In the Security and Acceptable Use Controls section, for File Inspection, click Edit.
- Enable File Inspection if it is not already enabled:

- Click Save.
- If you will enable file analysis using Cisco Secure Malware Analytics, see important information and follow the procedure in Enable File Analysis by Cisco Secure Malware Analytics.
- In the same Web profile, ensure that Decryption is enabled.
- Choose a Web profile that has file inspection enabled when you configure internet access rules.
Manage File Inspection < Enable File Inspection > Enable File Analysis by Cisco Secure Malware Analytics
Updated about 5 hours ago