Cisco Secure Access Help

PDF

Cisco Secure Access Help

Enable File Inspection

Want to summarize with AI?

Log in

Describes Enable File Inspection in Cisco Secure Access. To inspect files for threats, enable the file inspection features in security profiles for internet and private access, then assign the security profiles to internet and private access rules.


To inspect files for threats, enable the file inspection features in security profiles for internet and private access, then assign the security profiles to internet and private access rules.

File Inspection uses multiple features to evaluate for malicious files. For details, see Manage File Inspection and Analysis.

Once inspections are complete, a file is either delivered to the end user or the connection is terminated and the user is shown a block page.

Once you have enabled File Inspection, to monitor and review Umbrella's inspection activities, use the Security Activity and Activity Search reports.


Prerequisites for Enable File Inspection


Procedure for Enable File Inspection

Procedure

  1. Navigate to Secure > Security Profiles.

  2. Click +Add Profile or expand an existing profile.

  3. In the Security and Acceptable Use Controls section, for File Inspection, click Edit.

  4. Enable File Inspection if it is not already enabled:


    File inspection section with option to edit and enable file inspection
  5. Click Save.

  6. If you will enable file analysis using Cisco Secure Malware Analytics, see important information and follow the procedure in Enable File Analysis by Cisco Secure Malware Analytics.

  7. For security profiles for internet access: In the same profile, ensure that Decryption is enabled.

  8. For security profiles for private access: Ensure that destinations configured in the rule are configured as Private Resources with decryption enabled.

  9. Choose a security profile that has file inspection enabled when you configure access rules.