hi all,
as this is my first post on here please forgive me if i'm not fully confirming to board standards 😉 let me know and i will adjust 🙂
the thing i have noticed is that our firewall quite often allows for virus infected emails to pass trough the firewall altough our antivirus blade and antispam blades are turned on. i have been looking at the configuration and as far as i could see this should just work.
Please let me start with explaining how the email flow is setup at our end,
the email is first delivered to our Spam Filter in our DMZ this is the first time the traffic passes the firewall with protocol inspection then the spam filter does it's magic on the mail and then passes the email to our exchange server in a second DMZ so passing the firewall a second time. and again doing protocol inspection.
the other day i had an Endpoint Security allert again from our ESET virus scanner on a client system telling me that it had found and deleted a Virus from the system: trojan;VBA/TrojanDownloader.Agent.DZ
i'm starting to doubt that the protocol inspection and AntiVirus - AntiSpam blades do not function the correct way. as i have been searching for the issue for a bout 6 months now also together with support i thought lets ask the experts on the Checkmates Forum.
what can i do / test / check to make sure the firewall pick out these emails containing this kind of nasty attachments ?