Skip to main content

Marware and File Policy

Location in GUI: Policies » Marware and File » Marware and File Policies

Diagram

Classes

policies (fmc.domains)

NameTypeConstraintMandatoryDefault Value
file_policiesList[file_policies]No

file_policies (fmc.domains.policies)

NameTypeConstraintMandatoryDefault Value
nameStringRegex: ^[a-zA-Z0-9_.+ -]{1,64}$Yes
block_encrypted_archivesBooleantrue, falseNo
block_uninspectable_archivesBooleantrue, falseNo
clean_listBooleantrue, falseNo
custom_detection_listBooleantrue, falseNo
descriptionStringmax: 255No
first_time_file_analysisBooleantrue, falseNo
inspect_archivesBooleantrue, falseNo
max_archive_depthIntegermin: 1, max: 3No
threat_scoreChoiceDISABLED, MEDIUM, High, VERY_HIGHNo
file_rulesList[file_rules]No

file_rules (fmc.domains.policies.file_policies)

NameTypeConstraintMandatoryDefault Value
actionChoiceDETECT, BLOCK_WITH_RESET, DETECT_MALWARE, BLOCK_MALWARE_WITH_RESETYes
application_protocolChoiceANY, HTTP, SMTP, IMAP, POP3, FTP, SMBYes
direction_of_transferChoiceANY, UPLOAD, DOWNLOADYes
file_categoriesListStringNo
file_typesListStringNo
store_filesChoiceMALWARE, CUSTOM, CLEAN, UNKNOWNNo

Examples

Prerequisites:

existing:
fmc:
domains:
- name: Global
objects:
file_types:
- name: PDF
file_categories:
- name: PDF files

File Policy:

fmc:
domains:
- name: Global
policies:
file_policies:
- name: MyFilePolicyName1
file_rules:
- default_action: DETECT
application_protocol: HTTP
direction_of_transfer: DOWNLOAD
file_categories:
- PDF files
- default_action: DETECT
application_protocol: HTTP
direction_of_transfer: UPLOAD
file_types:
- PDF