Enable File Inspection

To inspect files for threats, enable the file inspection features in security profiles for internet and private access, then assign the security profiles to internet and private access rules.

File Inspection uses multiple features to evaluate for malicious files. For details, see Manage File Inspection and Analysis.

Once inspections are complete, a file is either delivered to the end user or the connection is terminated and the user is shown a block page.

Once you have enabled File Inspection, to monitor and review Umbrella's inspection activities, use the Security Activity and Activity Search reports.

Table of Contents

Prerequisites

Procedure

  1. Navigate to Secure > Security Profiles.
  2. Click +Add Profile or expand an existing profile.
  3. In the Security and Acceptable Use Controls section, for File Inspection, click Edit.
  4. Enable File Inspection if it is not already enabled:
  1. Click Save.
  2. If you will enable file analysis using Cisco Secure Malware Analytics, see important information and follow the procedure in Enable File Analysis by Cisco Secure Malware Analytics.
  3. For security profiles for internet access: In the same profile, ensure that Decryption is enabled.
  1. For security profiles for private access: Ensure that destinations configured in the rule are configured as Private Resources with decryption enabled.
  2. Choose a security profile that has file inspection enabled when you configure access rules.

Manage File Inspection < Enable File Inspection > Enable File Analysis by Cisco Secure Malware Analytics