Deep inspection using file and intrusion policies
Deep inspection is a security mechanism that uses intrusion and file policies as the last line of defense before traffic is allowed to its destination.
Policy types and capabilities
Deep inspection uses two types of policies to analyze traffic:
-
Intrusion policies govern the system's intrusion prevention capabilities.
-
File policies govern the system's file control and malware defense capabilities.
Access control occurs before deep inspection; access control rules and the access control default action determine which traffic is inspected by intrusion and file policies.
By associating an intrusion or file policy with an access control rule, you are telling the system that before it passes traffic that matches the access control rule's conditions, you first want to inspect the traffic with an intrusion policy, a file policy, or both.
In an access control policy, you can associate one intrusion policy with each Allow and Interactive Block rule, as well as with the default action. Every unique pair of intrusion policy and variable set counts as one policy.
Note | By default, the system disables intrusion and file inspection of encrypted payloads. This helps reduce false positives and improve performance when an encrypted connection matches an access control rule that has intrusion and file inspection configured. |
To associate intrusion and file policies with an access control rule, see:
For more information about intrusion policies, see Network Analysis and Intrusion Policy Basics.
For more information about file policies, see File Policies for Network Malware Protection.