Use SSQ insteadIn general, we recommend to enable the SSQ instead of attachment removal. It provides a safer environment and no attachments are lost.
- Verdict based: Remove all attachments from emails classified as Malware or Filter/Policy.
- File based: Remove attachments that match certain file criteria (e.g. extension)
- Custom rule based: Remove attachments based on arbitrary custom rules - contact support@xorlab.com for this
-
Open the
activeguard/core/rule_sets/90_local/params/local.propertiesfile in Expert Editor and add:local.properties -
Specify the email direction on which attachment removal is activated:
local.properties
-
For verdict based attachment removal, use the following configuration:
local.properties
-
For file based attachment removal, use the following configuration:
local.properties
- Attachment removal based on blacklists only works if the quarantine action for blacklist matches is disabled. If you need help adjusting this setting, contact support@xorlab.com.
-
For every use case above, you can specify the text in the replacement file with the following properties:
local.properties
- Click Publish. The rule-set configuration becomes active within about one minute.