Fortinet white logo
Fortinet white logo

CLI Reference

file content-disarm-reconstruct

file content-disarm-reconstruct

Use this command to configure content disarm and reconstruction (CDR) file attachment options.

Syntax

config file content-disarm-reconstruct

set component-type-options {...}

set metadata-type-option {...}

set continue-sandbox-on-cdr {enable | disable}

set deferred-scan-notification-option {disarm | remove}

set deferred-scan-notification-status {enable | disable}

set deferred-scan-verdict-option {clean | high | low | malicious | medium}

set deferred-scan-verdict-status {enable | disable}

set modification-notice-option {enable | disable}

end

Variable

Description

Default

component-type-options {...}

Select which attachment content types will receive CDR:

  • office-action

  • office-dde

  • office-embedded-object

  • office-hyperlink

  • office-linked-object

  • office-macro

  • office-metadata

  • pdf-action-form

  • pdf-action-gotor

  • pdf-action-javascript

  • pdf-action-launch

  • pdf-action-movie

  • pdf-action-sound

  • pdf-action-url

  • pdf-hyperlink

office-macro office-hyperlink office-linked-object office-embedded-object pdf-javascript pdf-embedded-file pdf-action-gotor pdf-action-launch pdf-action-url pdf-action-sound pdf-action-movie pdf-action-javascript pdf-action-form pdf-hyperlink office-dde office-action office-metadata

continue-sandbox-on-cdr {enable | disable}

By default, when CDR succeeds in disarming the attachment, the FortiSandbox scan is bypassed. Enable this option if you want to still perform the FortiSandbox scan, regardless of CDR result.

disable

deferred-scan-notification-option {disarm | remove}

Select whether to send notification email with a disarmed attachment, or with no attachment.

disarm

deferred-scan-notification-status {enable | disable}

Enable or disable sending the notification email on deferred scan.

disable

deferred-scan-verdict-option {clean | high | low | malicious | medium}

Select which verdict threshold to disarm on delivery.

clean

deferred-scan-verdict-status {enable | disable}

Enable or disable disarming the attachment of deferred email by verdict threshold.

enable

metadata-type-option {...}

Select which document property metadata to remove from attachment files during CDR:

  • office-comment — Comments about the file.

  • office-field — Fields such as the file creation date.

  • office-footnote — Endnotes and footnotes.

  • office-hidden-text — Hidden text. This does not include text that is invisible due to small font size, font color that is the same as the background, and other formatting.

  • office-property — Authors and other fields that could potentially be personally identifiable information (PII). PII is protected by law under some jurisdictions.

  • office-template — Template that may contain corporate font names, style settings, and more.

  • office-track-change — Tracked changes during review.

  • office-version — Previous revisions of the document.

  • office-watermark — Watermarked backgrounds. Does not include text and images that may resemble watermarks, but have been overlayed by another method such as frames or formatting.

office-template office-property office-version office-comment office-track-change office-field office-hidden-text office-footnote office-watermark

modification-notice-option {enable | disable}

Enable or disable appending the CDR notification Attachment has been reconstructed for cleaned attachments.

disable

Related topics

profile content

system fortiguard url-protection

system fortisandbox

file content-disarm-reconstruct

file content-disarm-reconstruct

Use this command to configure content disarm and reconstruction (CDR) file attachment options.

Syntax

config file content-disarm-reconstruct

set component-type-options {...}

set metadata-type-option {...}

set continue-sandbox-on-cdr {enable | disable}

set deferred-scan-notification-option {disarm | remove}

set deferred-scan-notification-status {enable | disable}

set deferred-scan-verdict-option {clean | high | low | malicious | medium}

set deferred-scan-verdict-status {enable | disable}

set modification-notice-option {enable | disable}

end

Variable

Description

Default

component-type-options {...}

Select which attachment content types will receive CDR:

  • office-action

  • office-dde

  • office-embedded-object

  • office-hyperlink

  • office-linked-object

  • office-macro

  • office-metadata

  • pdf-action-form

  • pdf-action-gotor

  • pdf-action-javascript

  • pdf-action-launch

  • pdf-action-movie

  • pdf-action-sound

  • pdf-action-url

  • pdf-hyperlink

office-macro office-hyperlink office-linked-object office-embedded-object pdf-javascript pdf-embedded-file pdf-action-gotor pdf-action-launch pdf-action-url pdf-action-sound pdf-action-movie pdf-action-javascript pdf-action-form pdf-hyperlink office-dde office-action office-metadata

continue-sandbox-on-cdr {enable | disable}

By default, when CDR succeeds in disarming the attachment, the FortiSandbox scan is bypassed. Enable this option if you want to still perform the FortiSandbox scan, regardless of CDR result.

disable

deferred-scan-notification-option {disarm | remove}

Select whether to send notification email with a disarmed attachment, or with no attachment.

disarm

deferred-scan-notification-status {enable | disable}

Enable or disable sending the notification email on deferred scan.

disable

deferred-scan-verdict-option {clean | high | low | malicious | medium}

Select which verdict threshold to disarm on delivery.

clean

deferred-scan-verdict-status {enable | disable}

Enable or disable disarming the attachment of deferred email by verdict threshold.

enable

metadata-type-option {...}

Select which document property metadata to remove from attachment files during CDR:

  • office-comment — Comments about the file.

  • office-field — Fields such as the file creation date.

  • office-footnote — Endnotes and footnotes.

  • office-hidden-text — Hidden text. This does not include text that is invisible due to small font size, font color that is the same as the background, and other formatting.

  • office-property — Authors and other fields that could potentially be personally identifiable information (PII). PII is protected by law under some jurisdictions.

  • office-template — Template that may contain corporate font names, style settings, and more.

  • office-track-change — Tracked changes during review.

  • office-version — Previous revisions of the document.

  • office-watermark — Watermarked backgrounds. Does not include text and images that may resemble watermarks, but have been overlayed by another method such as frames or formatting.

office-template office-property office-version office-comment office-track-change office-field office-hidden-text office-footnote office-watermark

modification-notice-option {enable | disable}

Enable or disable appending the CDR notification Attachment has been reconstructed for cleaned attachments.

disable

Related topics

profile content

system fortiguard url-protection

system fortisandbox