Security Add-ons
Gateway antivirus, IDS/IPS, spam filtering, SSL inspection, sandboxing, and botnet blocking extend protection depth.

Overview
Optional security services inspect content and traffic at the gateway-detecting exploits with IDS/IPS, decrypting where policy allows, scanning files in isolation, and cutting off command-and-control channels before malware establishes persistence.
Capabilities in this category
Antivirus/anti-malware gateway scanning
Scan downloads and attachments at the perimeter before delivery.
Multi-engine antivirus inspects HTTP, FTP, and email payloads for known malware. Automatic signature updates and heuristic analysis catch variants that evade single-engine detection.
Intrusion Detection/Prevention System (IDS/IPS)
Detect and block exploits, scans, and known attack signatures in-line.
Inline IPS inspects traffic against signature and behavioral rules, dropping malicious sessions before they reach internal assets. IDS mode logs suspicious activity for SOC review while optional prevention rules automate blocking at wire speed.
Anti-spam filtering
Filter unsolicited and phishing email at the network edge.
Reputation-based and content-aware spam filters reduce inbox noise and phishing risk. Quarantine, tagging, and allow/deny lists give administrators control over false positives without exposing users to bulk threats.
SSL/TLS inspection (decrypt and inspect encrypted traffic)
Decrypt HTTPS traffic for policy and threat inspection where permitted.
Forward-proxy and transparent inspection modes decrypt SSL/TLS sessions using enterprise CA certificates, applying URL, antivirus, and DLP policies to encrypted traffic that would otherwise bypass controls.
Sandboxing for unknown files/threats
Detonate suspicious files in an isolated environment before release.
Files that fail initial static checks are executed in a sandbox to observe behavior-registry changes, network callbacks, and encryption attempts-before a verdict allows or blocks delivery to the user.
Botnet and command-and-control (C2) traffic blocking
Block outbound connections to known botnet infrastructure.
Real-time threat feeds identify C2 domains and IPs associated with ransomware and botnets. Automated blocking severs infected hosts from their controllers while alerting the security team for remediation.
