Athena NGFW (Next-Generation Firewall)

Athena NGFW (previously known as Network Secure) provides comprehensive protection for every network perimeter, ensuring the safety of your valuable assets, data, and users from emerging threats.
{{ $t('productDocDetail.guideClickSwitch') }}
{{ $t('productDocDetail.know') }}
{{ $t('productDocDetail.dontRemind') }}
8.0.107
{{sendMatomoQuery("Athena NGFW (Next-Generation Firewall)","Phishing Email Protection")}}

Phishing Email Protection

{{ $t('productDocDetail.updateTime') }}: 2026-02-05

The Phishing Email Protection feature of Athena NGFW deeply integrates the powerful language comprehension capabilities of AI large models (GPT) with extensive data from the cloud intelligence library to construct a dynamic security defense system that efficiently coordinates local and cloud services. Phishing Email Protection can parse inbound email content in real time, and accurately identify spoofing, phishing links, and malicious attachments. In addition, this feature can issue real-time alerts for abnormal emails based on the risk assessment result, dynamically block access to malicious URLs, and coordinate with Endpoint Secure to synchronously quarantine high-risk attachments to fully eliminate the threats. Phishing Email Protection can automatically thwart attack chains without affecting user operations, and can effectively prevent enterprise financial losses and data leakage risks, thereby ensuring enterprise asset security.

Before you use the Phishing Email Protection feature, make sure that Athena NGFW is properly connected to Platform-X and that Phishing Email Protection in SOC > Next-Gen Security > Product Integration > Cloud Products is in the Normal state.

In addition, you need to go to SOC > Next-Gen Security > Cloud-Based Protection > Phishing Email Protection > Mailbox Protection to properly configure enterprise mailbox settings, to ensure that Athena NGFW can receive emails and coordinate with the GPT large model in the cloud to perform security checks.

Mailbox Type: Select the mailbox type used by your enterprise or add a custom mailbox type.

Protocol: Select IMAP or POP3 as needed.

Account: Enter the email account that Athena NGFW uses to receive enterprise emails.

Password: Enter the password of the email account that Athena NGFW uses to receive enterprise emails.

Email Server: Enter the address of the IMAP or POP3 mail server corresponding to the foregoing email account.

Port: Enter the port used by the mail server.

SSL: Select this check box if the email account uses SSL for encrypted communication.

STARTTLS: Select this check box if the email account uses STARTTLS for encrypted communication.

Test Connectivity: Click Test Connectivity to test the connectivity to the mail server. If the connectivity test is successful, the configurations are correct.

Auto Deletion: If this check box is selected, the emails synchronized to the corresponding account used by Athena NGFW will be automatically deleted after Athena NGFW forwards these emails to the cloud GPT large model for detection.

After the mailbox settings are properly configured, click OK. Then, you can view that the connection status of the mailbox is Normal on the Mailbox Protection tab.

Quarantine Phishing Attachments[zyl10]

Alert Settings

To ensure that the recipients and administrators can be timely alerted when Athena NGFW detects a phishing email, you need to further configure alert settings. Specifically, on the Mailbox Protection tab, click Edit next to Alert Settings to configure alert settings as needed, as shown in the following figure.

Sender settings:

Mailbox Type: Select the mailbox type used by your enterprise or add a custom mailbox type.

Account: Enter the email account that Athena NGFW uses to send alert emails.

Password: Enter the password of the email account that Athena NGFW uses to send alert emails.

Email Server: Enter the address of the SMTP mail server corresponding to the foregoing email account.

Port: Enter the port used by the mail server.

SSL: Select this check box if the email account uses SSL for encrypted communication.

STARTTLS: Select this check box if the email account uses STARTTLS for encrypted communication.

Test Connectivity: Click Test Connectivity to test the connectivity to the mail server. If the connectivity test is successful, the configurations are correct.

Recipients settings:

Alert Scope: Select All Recipients and/or Only Administrators as needed.

All Recipients: If this check box is selected, Athena NGFW will send an alert email to all recipients of a phishing email when the phishing email is detected by Athena NGFW.

Only Administrators: If this check box is selected, Athena NGFW will send an alert email to the specified administrator email account when a phishing email is detected by Athena NGFW.

Send Test Email: After Only Administrators is selected, you can click Send Test Email to send a test email to the specified administrator email account to verify whether the configuration is correct.

Phishing Links

The Phishing Email Protection feature can detect whether an email contains a malicious URL or a malicious file. If the email contains a malicious URL or malicious file, this malicious element will be automatically synchronized to the on-premises security database of Athena NGFW.

To effectively prevent users from accessing malicious URLs or downloading malicious files, you need to configure botnet detection and content security policies based on the user scope in advance.

The following figure shows that a phishing link is detected.

The following figure shows that the phishing link is automatically added to the on-premises URL category.

The following figure shows that the access to the phishing link from the PC is blocked by Athena NGFW.

Phishing Attachments

After identifying that an attachment in an email is a malicious file, the Phishing Email Protection feature can synchronize the MD5 hash of the file to the on-premises security database of Athena NGFW. If Athena NGFW is integrated with Endpoint Secure (V6.0.4ENR4 or later), Endpoint Secure will automatically quarantine the malicious file downloaded by the user without the need for additional configurations.

  1. Athena NGFW pushes the MD5 hash of the malicious file to Endpoint Secure.

  1. Endpoint Secure quarantines the malicious file.