Antispam
Antispam
FortiGate Version 4.0 Administration Guide
01-400-89802-20090424
495
•
Antispam
This chapter describes how to configure FortiGate spam filtering for IMAP, POP3, and
SMTP email. If your FortiGate unit supports SSL content scanning and inspection you can
also configure spam filtering for IMAPS, POP3S, and SMTPS email traffic. For information
about SSL content scanning and inspection, see
“SSL content scanning and inspection”
.
If you enable virtual domains (VDOMs) on the FortiGate unit, Antispam is configured
separately for each virtual domain. For details, see
“Using virtual domains” on page 103
This section describes:
•
•
•
IP address and email address black/white lists
•
Advanced antispam configuration
•
Using wildcards and Perl regular expressions
Antispam
You can configure the FortiGate unit to manage unsolicited commercial email by detecting
and identifying spam messages from known or suspected spam servers.
The
uses both a sender IP reputation database and a spam
signature database, along with sophisticated spam filtering tools, to detect and block a
wide range of spam messages. Using FortiGuard Antispam protection profile settings you
can enable IP address checking, URL checking, E-mail checksum check, and Spam
submission. Updates to the IP reputation and spam signature databases are provided
continuously via the global FortiGuard distribution network.
page in the FortiGuard center you can use IP and
signature lookup to check whether an IP address is blacklisted in the FortiGuard antispam
IP reputation database, or whether a URL or email address is in the signature database.
Order of spam filtering
The FortiGate unit checks for spam using various filtering techniques. The order the
FortiGate unit uses these filters depends on the mail protocol used.
Filters requiring a query to a server and a reply (FortiGuard Antispam Service and
DNSBL/ORDBL) are run simultaneously. To avoid delays, queries are sent while other
filters are running. The first reply to trigger a spam action takes effect as soon as the reply
is received.
Each spam filter passes the email to the next if no matches or problems are found. If the
action in the filter is Mark as Spam, the FortiGate unit tags as spam the email according to
the settings in the protection profile.
For SMTP and SMTPS if the action is discard the email message is discarded or dropped.
If the action in the filter is Mark as Clear, the email is exempt from any remaining filters. If
the action in the filter is Mark as Reject, the email session is dropped. Rejected SMTP or
SMTPS email messages are substituted with a configurable replacement message.
Summary of Contents for Gate 60D
Page 705: ...www fortinet com...
Page 706: ...www fortinet com...