This section describes how to configure push information for the APT defense feature.
The FW sends notifications in the text or web page format to users. You can specify the content of the notifications. To modify a notification, export the notification template, edit the notification in the template, and import the template file into the FW.
When you set the mail protocol action to Declare or Delete Attachment for file reputation detection in the APT defense profile, a warning message will be added to the body of emails identified as malicious.
In the Email Declaration and Email Delete Attachment notification templates, parameter %FILE indicates the name of the threat-infected file. Each notification message must contain only one %FILE. The FW automatically substitutes %FILE with the actual value when sending notification messages. The notification messages support spaces and can contain a maximum of 1024 characters.
You can perform the following operations to modify notifications or restore default notifications:
Click Export of the notification to be modified to download the notification file. Then edit the downloaded notification and import the file into the FW.
Click Reset corresponding to the notification to be modified to restore the default notification in the current virtual system.
If you perform the reset operation in the root system, the root system uses the default notification of the FW.
If you perform the reset operation in the virtual system, the virtual system uses the notification configured in the root system; if the default notification of the root system has not been modified before you perform the reset operation, the virtual system uses the default notification of the FW.