How to create a file extension exclusion from Gateway Antivirus inspection

Description

This article show how to create exclusions for file extension from a Gateway Antivirus inspection or block 

Resolution for SonicOS 7.X

This release includes significant user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.


  1. Login to the firewall
  2. Navigate to OBJECT | Match Objects
  3. Click +Add
  4. Insert a name
  5. Match Object Type as Custom Object. This method will be more broadly to match the traffic with the given values.
  6. Content: Insert the file extension. In this example, we are using .xlsm
  7. Click + Add
  8. Click Save.
    Image
  9. Navigate to POLICY | Rules and Policies | App Rules
  10. Click + Add
  11. Insert a name to the AppRule.
  12. Policy type as Custom Policy
  13. Match Object Included: Select the Match Object created.
  14. Action Object: Bypass GAV
  15. Connection Side as Both
  16. Direction as Both
  17. Click OK
    Image

Now the files with the extension configured should bypass the GAV inspection

Resolution for SonicOS 6.5

This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.


  1. Login to the Firewall
  2. Navigate to MANAGE | Objects | Match Objects
  3. Click Add
  4. Insert a name
  5. Match Object Type as Custom Object. This method will be more broadly to match the traffic with the given values.
  6. Content: Insert the file extension. In this example, we are using .xlsm
  7. Click Add
  8. Click OK.
    Image
  9. Navigate to MANAGE | Rules | App Rules
  10. Click Add
  11. Insert a name to the AppRule.
  12. Policy type as Custom Policy
  13. Match Object: Select the Match Object created.
  14. Action Object: Bypass GAV
  15. Connection Side as Both
  16. Direction as Both
  17. Click OK
    Image

Now the files with the extension configured should bypass the GAV inspection

Related Articles

  • How to block ICMP (Ping ) using Application control
    Read More
  • SonicWall GEN8 TZ and NSa Firewalls FAQ
    Read More
  • How to configure Link Aggregation
    Read More
not finding your answers?