Fortinet white logo
Fortinet white logo

CLI Reference

mailsetting mail-scan-option

mailsetting mail-scan-option

Use this command to configure how FortiMail scans compressed files such as ZIP archives.

Syntax

config mailsetting mail-scan-option

set personal-quarantine-attachment-scan {enable | disable}

set scan-timeout-value <seconds_int>

set scan-timeout-action {tempfail | passthrough}

set decompress-max-level <level_int>

set decompress-max-ratio <ratio_int>

set decompress-max-size <size_int>

set content-scan-level {high | low | medium}

set scan-microsoft-msg {enable | disable}

end

Variable

Description

Default

content-scan-level {high | low | medium}

Select the scan level of dictionary and DLP rules.

When set to medium or high, FortiMail uses recursive regular expressions to find a match, which consumes more system resources.

medium

decompress-max-level <level_int>

Enter how many levels to decompress the archived files for antivirus and content scan. Valid range is 1 to 36.

12

decompress-max-ratio <ratio_int>

Enter the maximum compression ratio for FortiMail to decompress. Valid range is 1 to 1000.

200

decompress-max-size <size_int>

Enter the maximum file size in megabytes (MB) to scan after the archived files are decompressed. This applies to every file after decompression. Bigger files will not be scanned.

10

personal-quarantine-attachment-scan {enable | disable}

For email that is sent to personal quarantine, select whether to continue or stop later scans of the email's attachments.

disable

scan-microsoft-msg {enable | disable}

Enable to scan attachments in Microsoft Transport Neutral Encapsulation format (TNEF) and MSG file formats.

enable

scan-timeout-action {tempfail | passthrough}

When the email attachments are large and the email scan has timed out, select whether FortiMail will reply to the SMTP client with an SMTP temporary failure code, or skip later scans.

tempfail

scan-timeout-value <seconds_int>

Enter the maximum amount of time in seconds that FortiMail should spend on scanning email contents. Valid range is 270 to 900.

Also configure scan-timeout-action {tempfail | passthrough}.

285

Related topics

mailsetting relay-host-list

mailsetting storage central-quarantine

mailsetting storage central-quarantine

mailsetting systemquarantine

mailsetting mail-scan-option

mailsetting mail-scan-option

Use this command to configure how FortiMail scans compressed files such as ZIP archives.

Syntax

config mailsetting mail-scan-option

set personal-quarantine-attachment-scan {enable | disable}

set scan-timeout-value <seconds_int>

set scan-timeout-action {tempfail | passthrough}

set decompress-max-level <level_int>

set decompress-max-ratio <ratio_int>

set decompress-max-size <size_int>

set content-scan-level {high | low | medium}

set scan-microsoft-msg {enable | disable}

end

Variable

Description

Default

content-scan-level {high | low | medium}

Select the scan level of dictionary and DLP rules.

When set to medium or high, FortiMail uses recursive regular expressions to find a match, which consumes more system resources.

medium

decompress-max-level <level_int>

Enter how many levels to decompress the archived files for antivirus and content scan. Valid range is 1 to 36.

12

decompress-max-ratio <ratio_int>

Enter the maximum compression ratio for FortiMail to decompress. Valid range is 1 to 1000.

200

decompress-max-size <size_int>

Enter the maximum file size in megabytes (MB) to scan after the archived files are decompressed. This applies to every file after decompression. Bigger files will not be scanned.

10

personal-quarantine-attachment-scan {enable | disable}

For email that is sent to personal quarantine, select whether to continue or stop later scans of the email's attachments.

disable

scan-microsoft-msg {enable | disable}

Enable to scan attachments in Microsoft Transport Neutral Encapsulation format (TNEF) and MSG file formats.

enable

scan-timeout-action {tempfail | passthrough}

When the email attachments are large and the email scan has timed out, select whether FortiMail will reply to the SMTP client with an SMTP temporary failure code, or skip later scans.

tempfail

scan-timeout-value <seconds_int>

Enter the maximum amount of time in seconds that FortiMail should spend on scanning email contents. Valid range is 270 to 900.

Also configure scan-timeout-action {tempfail | passthrough}.

285

Related topics

mailsetting relay-host-list

mailsetting storage central-quarantine

mailsetting storage central-quarantine

mailsetting systemquarantine