file content-disarm-reconstruct
Use this command to configure content disarm and reconstruction (CDR) file attachment options.
Syntax
config file content-disarm-reconstruct
set component-type-options {...}
set metadata-type-option {...}
set continue-sandbox-on-cdr {enable | disable}
set deferred-scan-notification-option {disarm | remove}
set deferred-scan-notification-status {enable | disable}
set deferred-scan-verdict-option {clean | high | low | malicious | medium}
set deferred-scan-verdict-status {enable | disable}
set modification-notice-option {enable | disable}
end
|
component-type-options {...}
|
Select which attachment content types will receive CDR:
-
office-action
-
office-dde
-
office-embedded-object
-
office-hyperlink
-
office-linked-object
-
office-macro
-
office-metadata
-
pdf-action-form
-
pdf-action-gotor
-
pdf-action-javascript
-
pdf-action-launch
-
pdf-action-movie
-
pdf-action-sound
-
pdf-action-url
-
pdf-hyperlink
|
office-macro office-hyperlink office-linked-object office-embedded-object pdf-javascript pdf-embedded-file pdf-action-gotor pdf-action-launch pdf-action-url pdf-action-sound pdf-action-movie pdf-action-javascript pdf-action-form pdf-hyperlink office-dde office-action office-metadata
|
|
continue-sandbox-on-cdr {enable | disable}
|
By default, when CDR succeeds in disarming the attachment, the FortiSandbox scan is bypassed. Enable this option if you want to still perform the FortiSandbox scan, regardless of CDR result.
|
disable
|
|
deferred-scan-notification-option {disarm | remove}
|
Select whether to send notification email with a disarmed attachment, or with no attachment.
|
disarm
|
|
deferred-scan-notification-status {enable | disable}
|
Enable or disable sending the notification email on deferred scan.
|
disable
|
|
deferred-scan-verdict-option {clean | high | low | malicious | medium}
|
Select which verdict threshold to disarm on delivery.
|
clean
|
|
deferred-scan-verdict-status {enable | disable}
|
Enable or disable disarming the attachment of deferred email by verdict threshold.
|
enable
|
|
metadata-type-option {...}
|
Select which document property metadata to remove from attachment files during CDR:
-
office-comment — Comments about the file.
-
office-field — Fields such as the file creation date.
-
office-footnote — Endnotes and footnotes.
-
office-hidden-text — Hidden text. This does not include text that is invisible due to small font size, font color that is the same as the background, and other formatting.
-
office-property — Authors and other fields that could potentially be personally identifiable information (PII). PII is protected by law under some jurisdictions.
-
office-template — Template that may contain corporate font names, style settings, and more.
-
office-track-change — Tracked changes during review.
-
office-version — Previous revisions of the document.
-
office-watermark — Watermarked backgrounds. Does not include text and images that may resemble watermarks, but have been overlayed by another method such as frames or formatting.
|
office-template office-property office-version office-comment office-track-change office-field office-hidden-text office-footnote office-watermark
|
|
modification-notice-option {enable | disable}
|
Enable or disable appending the CDR notification Attachment has been reconstructed for cleaned attachments.
|
disable
|
Related topics
profile content
system fortiguard url-protection
system fortisandbox