<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block Malicious Unknown File type attachment (MTA) (TE) (R80.20) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Malicious-Unknown-File-type-attachment-MTA-TE-R80-20/m-p/33813#M13417</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hiii &lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;Dameon Welch-Abernathy&lt;/A&gt;‌ thanks for the suggestion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still we unable to block after enabling &lt;STRONG&gt;Process all file types&lt;/STRONG&gt; option also.&lt;/P&gt;&lt;P&gt;As I can see .&lt;STRONG&gt;iso&lt;/STRONG&gt;&amp;nbsp;extension is not even on the list also but its block by &lt;STRONG&gt;TE&lt;/STRONG&gt; but when I change the extension to .der or .mht&amp;nbsp;then its allow the file to download.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any workaround for this issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in Advance&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#Chinmaya Naik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Feb 2019 06:02:56 GMT</pubDate>
    <dc:creator>Chinmaya_Naik</dc:creator>
    <dc:date>2019-02-19T06:02:56Z</dc:date>
    <item>
      <title>Block Malicious Unknown File type attachment (MTA) (TE) (R80.20)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Malicious-Unknown-File-type-attachment-MTA-TE-R80-20/m-p/33811#M13415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline; font-size: 15px;"&gt;&lt;STRONG&gt;Setup&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;MGMT Server : Open Server&lt;/P&gt;&lt;P&gt;Security Gateway : 15600&lt;/P&gt;&lt;P&gt;TE Appliance&lt;/P&gt;&lt;P&gt;MTA : Enabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Requirement&lt;/STRONG&gt;&lt;/SPAN&gt; &lt;STRONG&gt;:&amp;nbsp;&lt;/STRONG&gt;Our requirement is that Threat Emulation or Antivirus should drop the mail if any other or unknown extension is attach in the mail. (Currently Checkpoint TE and AV blade support more than 90 file type [AV] and 65 file type by [TE] )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="78497" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/78497_pastedImage_12.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Seanario1 :&lt;/STRONG&gt;&amp;nbsp; Our case we change the extension of malicious file to any known extension as listed on above and send a mail and here &lt;STRONG&gt;AV&lt;/STRONG&gt; is able to block the mail.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Seanario2 :&lt;/STRONG&gt; Suppose I change the&amp;nbsp; extension to any other or&amp;nbsp;unknown extension of that malicious file then here &lt;STRONG&gt;AV&lt;/STRONG&gt; is not able to block that mail.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Example :&lt;/STRONG&gt; File Name : samples.tar (malicious file)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;INTERNET ----&amp;gt;&amp;nbsp; MAIL (samples.tar mail attatchment ) -----&amp;gt;&amp;nbsp; BLOCK by TE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;INTERNET ----&amp;gt;&amp;nbsp; MAIL (samples.tar.pdf mail attatchment ) -----&amp;gt;&amp;nbsp; BLOCK by TE&amp;nbsp; (just changing the extension)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;INTERNET ----&amp;gt;&amp;nbsp; MAIL (&lt;STRONG&gt;samples.tar.mht&lt;/STRONG&gt; mail attatchment ) -----&amp;gt;&amp;nbsp; Allow and not able to find any log&amp;nbsp; (just changing the extension)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;INTERNET ----&amp;gt;&amp;nbsp; MAIL (&lt;STRONG&gt;samples.tar.der&lt;/STRONG&gt; mail attatchment ) -----&amp;gt;&amp;nbsp; Allow and not able to find any log&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;NOTE :&lt;/STRONG&gt;&lt;/SPAN&gt; We update the &lt;STRONG&gt;TE engine&lt;/STRONG&gt; to version&amp;nbsp; &lt;STRONG&gt;&lt;CODE&gt;58.990000298&lt;/CODE&gt;&lt;/STRONG&gt;. (sk92509)&lt;/P&gt;&lt;P&gt;Installed latest jumbo &lt;STRONG&gt;Take_33&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt; with &lt;STRONG&gt;MTA take_24&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per the &lt;STRONG&gt;sk121097&lt;/STRONG&gt; (Last update on&amp;nbsp;25-Oct-2017 )&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993366;"&gt;Threat Emulation is not scanning files if their extension was changed to unsupported file type&amp;nbsp;is an expected behavior.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;STRONG&gt;# Chinmaya Naik&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2019 06:23:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Malicious-Unknown-File-type-attachment-MTA-TE-R80-20/m-p/33811#M13415</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2019-02-15T06:23:19Z</dc:date>
    </item>
    <item>
      <title>Re: Block Malicious Unknown File type attachment (MTA) (TE) (R80.20)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Malicious-Unknown-File-type-attachment-MTA-TE-R80-20/m-p/33812#M13416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You realize there's an option to scan all file types with AV, right?&lt;/P&gt;&lt;P&gt;I'm not aware of an option to block all "unknown" extension types.&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/78527_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Feb 2019 00:08:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Malicious-Unknown-File-type-attachment-MTA-TE-R80-20/m-p/33812#M13416</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-16T00:08:56Z</dc:date>
    </item>
    <item>
      <title>Re: Block Malicious Unknown File type attachment (MTA) (TE) (R80.20)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Malicious-Unknown-File-type-attachment-MTA-TE-R80-20/m-p/33813#M13417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hiii &lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;Dameon Welch-Abernathy&lt;/A&gt;‌ thanks for the suggestion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still we unable to block after enabling &lt;STRONG&gt;Process all file types&lt;/STRONG&gt; option also.&lt;/P&gt;&lt;P&gt;As I can see .&lt;STRONG&gt;iso&lt;/STRONG&gt;&amp;nbsp;extension is not even on the list also but its block by &lt;STRONG&gt;TE&lt;/STRONG&gt; but when I change the extension to .der or .mht&amp;nbsp;then its allow the file to download.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any workaround for this issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in Advance&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#Chinmaya Naik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Feb 2019 06:02:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Malicious-Unknown-File-type-attachment-MTA-TE-R80-20/m-p/33813#M13417</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2019-02-19T06:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: Block Malicious Unknown File type attachment (MTA) (TE) (R80.20)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Malicious-Unknown-File-type-attachment-MTA-TE-R80-20/m-p/33814#M13418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Offhand don't know, but will ask around &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Feb 2019 16:17:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Malicious-Unknown-File-type-attachment-MTA-TE-R80-20/m-p/33814#M13418</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-19T16:17:40Z</dc:date>
    </item>
    <item>
      <title>Re: Block Malicious Unknown File type attachment (MTA) (TE) (R80.20)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Malicious-Unknown-File-type-attachment-MTA-TE-R80-20/m-p/33815#M13419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As I can see .&lt;STRONG&gt;iso&lt;/STRONG&gt;&amp;nbsp;file type is not&amp;nbsp;supported on AV but TE is supported so that file type (.iso) block by&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;TE&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;but when I change the extension to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;.der&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;or&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;.mht&lt;/STRONG&gt;&amp;nbsp;then its allow the file to download because that two file type is not supported by TE and AV.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per the&amp;nbsp;&lt;STRONG style="background-color: #ffffff; color: #000000; font-size: 14px; "&gt;sk123140&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;(How to configure Threat Emulation blade to block files according to file types) but as per our requirement is to block unknown filetype that not listed on AV and TE.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Thanks in Advance&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;SPAN style="color: #333333;"&gt;Hiii&amp;nbsp;&lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;Dameon Welch-Abernathy&lt;/A&gt;‌&lt;/SPAN&gt;&amp;nbsp;can&lt;SPAN style="color: #333333;"&gt;&lt;SPAN&gt; we move this question to sandblast section?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="background-color: #ffffff; color: #000000; font-size: 14px; "&gt;#Chinmaya Naik&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2019 06:19:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Malicious-Unknown-File-type-attachment-MTA-TE-R80-20/m-p/33815#M13419</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2019-02-20T06:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: Block Malicious Unknown File type attachment (MTA) (TE) (R80.20)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Malicious-Unknown-File-type-attachment-MTA-TE-R80-20/m-p/33816#M13420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Done.&lt;/P&gt;&lt;P&gt;Still checking with R&amp;amp;D &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Feb 2019 06:56:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Malicious-Unknown-File-type-attachment-MTA-TE-R80-20/m-p/33816#M13420</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-21T06:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: Block Malicious Unknown File type attachment (MTA) (TE) (R80.20)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Malicious-Unknown-File-type-attachment-MTA-TE-R80-20/m-p/33817#M13421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks &lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;Dameon Welch-Abernathy&lt;/A&gt;‌&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Waiting for your response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#Chinmaya Naik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Feb 2019 07:42:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Malicious-Unknown-File-type-attachment-MTA-TE-R80-20/m-p/33817#M13421</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2019-02-21T07:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: Block Malicious Unknown File type attachment (MTA) (TE) (R80.20)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Malicious-Unknown-File-type-attachment-MTA-TE-R80-20/m-p/50499#M13422</link>
      <description>&lt;P&gt;Hi, a little late, I realize, but it seems there is an option in the Threat Prevention profile to deal with unknown extensions:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image001.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/751i7482E04654C49D9A/image-size/large?v=v2&amp;amp;px=999" role="button" title="image001.png" alt="image001.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 23:34:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Malicious-Unknown-File-type-attachment-MTA-TE-R80-20/m-p/50499#M13422</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-04-10T23:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: Block Malicious Unknown File type attachment (MTA) (TE) (R80.20)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Malicious-Unknown-File-type-attachment-MTA-TE-R80-20/m-p/53003#M13423</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there an update to this issue?&lt;/P&gt;&lt;P&gt;Especially the mht files.&lt;/P&gt;&lt;P&gt;It seems that the Sandbox mht files does not recognize as files. That means blocking all unknown files does not work since the file is not detected.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Klaas&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2019 11:09:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Malicious-Unknown-File-type-attachment-MTA-TE-R80-20/m-p/53003#M13423</guid>
      <dc:creator>Klaas</dc:creator>
      <dc:date>2019-05-09T11:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: Block Malicious Unknown File type attachment (MTA) (TE) (R80.20)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Malicious-Unknown-File-type-attachment-MTA-TE-R80-20/m-p/53014#M13424</link>
      <description>The sandbox cannot emulate "unknown" file types but AV should block them if so configured.&lt;BR /&gt;If you've configure AV and the Threat Prevention profile as pictured above and it is still getting through, please open a TAC ticket.</description>
      <pubDate>Thu, 09 May 2019 13:36:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Block-Malicious-Unknown-File-type-attachment-MTA-TE-R80-20/m-p/53014#M13424</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-05-09T13:36:23Z</dc:date>
    </item>
  </channel>
</rss>

