The file inspection feature allows the Network Security appliance to inspect files that are detected in network traffic. When file inspection is enabled, files are compared to a blacklist. If a file matches the blacklist, it is marked as malicious. The malicious traffic is blocked and an alert is created. File inspection can match on IP addresses, URIs, domains, and streaming sessions as well as other files. Inspection of hash files can be enabled separately.
You can view detailed statistics of file inspection, as well as the configuration of the bot tracker preprocessor and preprocessor statistics.
Important
The file inspection feature is not supported on Trellix 10000 models.
Caution
Enabling file inspection may impact performance, especially latency, on the Network Security appliances working in inline mode.
The impact can vary depending on the capacity of the appliance and the volume of file traffic processed by the appliance. Under certain conditions, if an appliance receives at least 25 percent file traffic volume and operates at 50 percent of peak throughput, the latency can increase up to 1.5 to 2 times normal.