Managing Threat Prevention
R81.10.X Quantum Spark 1500, 1600, 1800, 1900, 2000 Appliances Locally Managed Administration Guide|278
Enabling Threat Emulation Policy for the FTP Protocol
Note - In the R81.10.X releases, this feature is available starting from the R81.10.05
version.
Move both the Anti-Virus and Threat Emulation sliders to ON.
Note - When the blade is managed by Cloud Services, a lock icon appears. You
cannot toggle between the "ON" and "OFF" states. If you change other policy
settings, the change is temporary. Any changes made locally are overridden in the
next synchronization between the gateway and Cloud Services.
The update status is displayed next to each blade:
n
Up to date
n
Update available
n
Update service unreachable
You can activate the blades to prevent attacks/infection or set them to detect-mode only on the
Threat Prevention Engine Settings page.
A warning message shows if a blade is in configured in the Detect-only mode.
The top of the page shows the number of infected devices. For more information, click More
details.
One policy is configured for all the blades:
n
Strict - Focuses on security.
n
Recommended - The default option, which gives the best mixture of security and
performance for small/medium sized business.
Note - The performance impact for the "Suspicious Mail Activity" protection in
Anti-Bot was changed to High and is now off by default. To enable this
protection, you must configure it in a custom policy.
n
Custom - Manually defined by the user.
Configuring a Custom Policy for Threat Prevention
1. In the Threat Prevention Blade Control page, under Policy, select Custom.
2. For Tracking options, select one of these options:
n
None – Do not log.
n
Log – Create a log.
n
Alert – Log with an alert.