Advanced Settings
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.40 Locally Managed Administration Guide | 146
Threat
Prevention
Anti-Virus
Policy Attribute
Description
File scan size
limit
Indicates the size limit (in KB) of a file scanned by Anti-Virus engine. To
specify no limit, set to 0.
MIME
maximum
nesting level
For emails that contain nested MIME content, set the maximum number of
levels that the ThreatSpect engine scans in the email.
MIME nesting
level exceeded
action
If there are more nested levels of MIME content than the configured
amount, select to
Block
or
Allow
the email file.
Priority
scanning
Scan according to security and performance priorities for maximum
optimization.
Resource
classification
mode
Indicates the mode used by the Anti-Virus engine for resource
classification:
n
Hold
- Connections are blocked until classification is complete.
When a connection cannot be classified with the cached responses,
it remains blocked until the Check Point Online Web Service
completes classification.
n
Background
- Connections are allowed until classification is
complete. When a connection cannot be classified with a cached
response, an uncategorized response is received. The connection is
allowed. In the background, the Check Point Online Web Service
continues the classification procedure. The response is then cached
locally for future requests. This option reduces latency in the
classification process.
Table: Threat Prevention Anti-Virus Policy Attributes
Threat Prevention Threat
Emulation Policy Attribute
Description
Emulation connection
handling mode - IMAP
Indicates the strictness mode of the Threat Emulation engine
over IMAP:
n
Background
- Connections are allowed while the file
emulation runs (if needed) until emulation handling is
complete.
n
Hold
- Connections are blocked until the file emulation is
completed
Table: Threat Prevention Threat Emulation Policy Attributes