354
Preventing attacks
Increasing productivity by identifying spam email
Related information
For further information related to this topic, see the following:
■
“Configuring and running LiveUpdate”
■
“Adding antispam protection to a rule”
■
“Understanding and using licenses”
Identifying spam using a custom known spammers list
You can configure the security gateway to identify spam email based on a list of sender addresses or
domains that you create.
The security gateway searches both the envelope From and message From headers to determine string
matches. If the exact address is not found, the security gateway looks for the wildcard representation
in the user part of the sender address. If the wildcard representation is not found, it looks for the
specific domain. If the specific domain is not found, the security gateway strips the first portion of the
domain, and the remaining portion is checked. This process continues until a match is found or until
the entire domain is parsed. For example:
If you configure the security gateway to block a subdomain (for example,
server.symantecdomain.com), it blocks only that subdomain and not the full domain (for example,
symantecdomain.com).
You can specify how you want to handle messages that are identified as spam by the custom known
spammers list. You can block the email message or send the message to the recipient unmodified.
Ensure that you enable the senders list setting in the appropriate security gateway rule. You must also
have a valid Firewall Base license. If you do not, the security gateway does not attempt to use this
antispam scanning process.
Note:
This feature is only available for the SMTP protocol.
Prerequisites
None.
To identify spam using a custom known spammers list
1
In the SGMI, in the left pane, under Policy, click
Antispam
.
2
In the right pane, on the Configuration tab, to the right of the Email senders identified as spam list,
click
Add
.
3
In the Senders identified as spam dialog box, do the following:
■
In the Sender Address text box, type the email address or fully qualified domain name.
■
Click
OK
.
Table 9-5
How to configure the email sender’s spam list
Task
Configuration
To deny a specific user
You can use a wildcard in the user name portion of the
address.
To deny all users at a specific domain
@symantecdomain.com
To deny all users at this domain and any subdomains
.symantecdomain.com
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...