cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Rule set block MediaType Exchange Online o365 Email

We want to create a rule to block the download of some types of files in the online exchange, but the domain where they are hosted is not possible is https://attachments.office.net,
when we try to download an example .zip file, it is downloaded without problem, we cannot view the file from the central rule tracing.

Regards.

 

4 Replies
mkutrieba
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 5

Re: Rule set block MediaType Exchange Online o365 Email

Hello @Wagner1991,

If you only see the full URL host in rule trace, then SSL/HTTPS scanning is bypassed so that MWG does not break the SSL traffic and can therefore not look inside the encrypted session. So you only see the URL host but not the files/paths in it, hence, you cannot filter for that.

In such cases, you must perform SSL/HTTPS scanning to let MWG at first look inside the encrypted session. Then you should see full requests to the files/paths and only then you can setup rules based on that.

If you have further troubles, I recommend to open a SR and attach feedback file, rule trace and mention your rule as this information is to sensitive for community.

Regards,
Marcel Kutrieba
Technical Support Engineer

If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!

Re: Rule set block MediaType Exchange Online o365 Email

Hi @mkutrieba ,

the URL host does not have SSL bypass, i will  open a case to support.


Thank you

asabban
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 4 of 5

Re: Rule set block MediaType Exchange Online o365 Email

Hello,

I assume attachments.office.net is bypassed from SSL inspection, which means you cannot look inside the traffic. The recommendation (Microsoft and McAfee) is to not intercept the traffic to ensure compatibility.

You can try to exclude attachments.office.net from any bypasses and check if the functionality is still given and you are able to see the media type in the rule traces as expected. If you see the media types you should be able to apply a block based on media type.

Re: Rule set block MediaType Exchange Online o365 Email

Hi @asabban 

the URL host does not have SSL bypass, i will  open a case to support.


Thank you

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community