The sending mail server receives a Code 550: denied by policy error message. The
appliance keeps a list of connections that are not allowed to send email under any
circumstances.
13 Test the configuration:
a Send an email from <client email address> to <server email address>.
b Create a text file that includes the following string:
X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
c Save the file as
eicar.txt
.
d Attach the file to the email.
The gateway security device replaces the file with an alert and the sender receives a
notification alert.
14 Return to Custom Malware Actions and select Specific detection name:
15 Type
EICAR
.
16 Set the custom action to Refuse the data and return an error code (Block), then click
OK.
17 From an external email account, create a message and attach the EICAR test file.
The email client returns with an error 550: denied by policy error message.
18 In Custom Actions, change the custom action to Deny connection (Block), then click
OK.
19 Send the same email and check the denied connection. It has the IP address of your client
machine (example IP address).
20 Try to send a benign email. This is also denied because of the denied connections list. To
the sending server, it appears that the server is not online.
The appliance checks the message as it enters your mail gateway and identifies that it contains
a virus. It quarantines the message and notifies the intended recipient and the sender that the
message was infected.
Creating an anti-spam scanning policy
Use this task to set up a policy to protect your organization from receiving unsolicited messages.
A policy like this protects users from receiving unsolicited email messages that reduce productivity
and increase the message traffic through your servers.
Task
1
On the appliance, ensure that you are using McAfee Quarantine Manager (Email |
Quarantine Configuration).
2
Select Email | Email Policies | Scanning Policies.
You must set up a separate anti-spam policy for the SMTP and POP3 protocols.
3
Set the primary action to Accept and drop the data.
4
Set the secondary action to Quarantine the original E-mail. Change the spam score to
5.
If you enable anti-spam detection, we recommend that you also enable anti-phishing
detection. Scanning performance is not impacted by performing both anti-spam and
anti-phish checks.
5
From an external email account, create a message to a mailbox protected by the appliance.
Exploring the Appliance
Using policies to manage message scanning
39
McAfee Email and Web Security Appliance 5.1 Installation Guide