Fortinet black logo

Use Case 1: Scanning ActiveSync Email Attachments

Copy Link
Copy Doc ID cda1d277-10bb-11ea-9384-00505692583a:458718

Use Case 1: Scanning ActiveSync Email Attachments

As ActiveSync delivers emails to devices, organizations need to make sure email attachments are scanned to ensure they do not carry any malware.

FortiWeb provides the ability to extract attachments from the mobile to mail server sessions, scan them using its embedded Antivirus engine, and send them to FortiSandbox for additional scanning.

First, make sure your web server supports ActiveSync and configured correctly. Here is an example for Microsoft Exchange:

Exchange 2010

  1. Open IIS Manager.
    1. Go to Microsoft-Server-ActiveSync.
    2. Make sure Basic Authentication is enabled.
  2. Open Exchange Management Console.
    1. Go to Client Access.
    2. Switch to Exchange ActiveSync on the bottom panel.
    3. Double click Microsoft-Server-ActiveSync (Default Web Site).
    4. Make sure:
      1. URLs are configured correctly.
      2. Basic authentication is enabled.
      3. Client certificate is ignored.

Exchange 2013/2016/2019

  1. Open your browser, and access Exchange admin center https://<exchange.server.com>/ecp.
  2. Log in with administrator credentials.
  3. Go to Microsoft-Server-ActiveSync (Default Web Site).
  4. Make sure the configurations are the similar to those of Exchange 2010 above.

FortiWeb Configuration

First, configure the File Security policy.

  1. Enable Trojan Detection for additional security. Make sure you enable Antivirus Scan and FortiSandbox.
  2. Enable Scan attachments in Email and choose ActiveSync in Protocol (possibly OWA too if you’re using FortiWeb to publish Exchange OWA as well).

    Now, attach the File Security policy to the Web Protection Profile. For more information on File Security, see Limiting file uploads in FortiWeb Administration Guide.

Next, create a new server policy. ActiveSync is usually used with SSL. So the front end and backend should be configured with HTTPS.

  1. Configure the front end (towards the client) options.
  2. Configure the backend (towards the server pool) options.

Now, open the mail application on your phone and test.

Use Case 1: Scanning ActiveSync Email Attachments

As ActiveSync delivers emails to devices, organizations need to make sure email attachments are scanned to ensure they do not carry any malware.

FortiWeb provides the ability to extract attachments from the mobile to mail server sessions, scan them using its embedded Antivirus engine, and send them to FortiSandbox for additional scanning.

First, make sure your web server supports ActiveSync and configured correctly. Here is an example for Microsoft Exchange:

Exchange 2010

  1. Open IIS Manager.
    1. Go to Microsoft-Server-ActiveSync.
    2. Make sure Basic Authentication is enabled.
  2. Open Exchange Management Console.
    1. Go to Client Access.
    2. Switch to Exchange ActiveSync on the bottom panel.
    3. Double click Microsoft-Server-ActiveSync (Default Web Site).
    4. Make sure:
      1. URLs are configured correctly.
      2. Basic authentication is enabled.
      3. Client certificate is ignored.

Exchange 2013/2016/2019

  1. Open your browser, and access Exchange admin center https://<exchange.server.com>/ecp.
  2. Log in with administrator credentials.
  3. Go to Microsoft-Server-ActiveSync (Default Web Site).
  4. Make sure the configurations are the similar to those of Exchange 2010 above.

FortiWeb Configuration

First, configure the File Security policy.

  1. Enable Trojan Detection for additional security. Make sure you enable Antivirus Scan and FortiSandbox.
  2. Enable Scan attachments in Email and choose ActiveSync in Protocol (possibly OWA too if you’re using FortiWeb to publish Exchange OWA as well).

    Now, attach the File Security policy to the Web Protection Profile. For more information on File Security, see Limiting file uploads in FortiWeb Administration Guide.

Next, create a new server policy. ActiveSync is usually used with SSL. So the front end and backend should be configured with HTTPS.

  1. Configure the front end (towards the client) options.
  2. Configure the backend (towards the server pool) options.

Now, open the mail application on your phone and test.