Forum-Breadcrumbs - Du bist hier:Knowledge BaseSecurity - Don't let perfect the enemy of good: Sophos UTM [SG, Astaro]How to troubleshoot Sophos Sandst …
Bitte Anmelden, um Beiträge und Themen zu erstellen.
How to troubleshoot Sophos Sandstorm
#1 · 3. Mai 2021, 14:48
Zitat von mpca am 3. Mai 2021, 14:48 Uhrhttps://support.sophos.com/support/s/article/KB-000036052?language=en_US
Troubleshooting Sandstorm in Web Protection
Check the web proxy log (http.log) for
sandbox
, which will have one of the following values:
Value Explanation -4
There was an issue with the UTM communicating with cloud, or the cloud responded that the file could not be sandboxed. -3
Sandbox considers the file malicious and it is blocked. The file was sent to the cloud. -2
The UTM could not communicate with the cloud server, or there is an internal error. -1
Sandbox considers the file malicious and it is blocked. The file was not sent to the cloud. -
SAV engine has determined the file should not be sandboxed. The file was not send to the cloud. 1
SAV engine has determined the file should be sandboxed. The system is not configured to sandbox the file. The file was not sent. 2
The file was sent to the cloud for further investigation. Results are pending. 3
Sandbox considers the file safe and it is allowed. The file was not sent to the cloud. 4
Sandbox considers the file safe and it is allowed. The file was sent to the cloud.
https://support.sophos.com/support/s/article/KB-000036052?language=en_US
Troubleshooting Sandstorm in Web Protection
Check the web proxy log (http.log) for sandbox
, which will have one of the following values:
Value | Explanation |
---|---|
-4 |
There was an issue with the UTM communicating with cloud, or the cloud responded that the file could not be sandboxed. |
-3 |
Sandbox considers the file malicious and it is blocked. The file was sent to the cloud. |
-2 |
The UTM could not communicate with the cloud server, or there is an internal error. |
-1 |
Sandbox considers the file malicious and it is blocked. The file was not sent to the cloud. |
- |
SAV engine has determined the file should not be sandboxed. The file was not send to the cloud. |
1 |
SAV engine has determined the file should be sandboxed. The system is not configured to sandbox the file. The file was not sent. |
2 |
The file was sent to the cloud for further investigation. Results are pending. |
3 |
Sandbox considers the file safe and it is allowed. The file was not sent to the cloud. |
4 |
Sandbox considers the file safe and it is allowed. The file was sent to the cloud. |