30.01.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

14.4 Email scanning<br />

Figure 14.9<br />

Settings for SMTP and POP3 scanning<br />

Note: Regardless of what action is set to be taken, the attachment is always removed and<br />

a warning message is attached instead.<br />

Use the TLS connections section to set firewall behavior for cases where both mail client and<br />

the server support TLS-secured SMTP or POP3 traffic.<br />

In case that TLS protocol is used, unencrypted connection is established first. Then, client<br />

and server agree on switching to the secure mode (encrypted connection). If the client or the<br />

server does not support TLS, encrypted connection is not used and the traffic is performed in<br />

a non-secured way.<br />

If the connection is encrypted, firewall cannot analyze it and perform antivirus check for<br />

transmitted messages. The firewall administrator can select one of the following alternatives:<br />

• Enable TLS. This alternative is suitable for such cases where protection from<br />

wiretapping is prior to antivirus check of email.<br />

Hint:<br />

In such cases, it is recommended to install an antivirus engine at<br />

individual hosts that would perform local antivirus check.<br />

• Disable TLS. Secure mode will not be available. Clients will automatically assume<br />

that the server does not support TLS and messages will be transmitted through an<br />

unencrypted connection. Firewall will perform antivirus check for all transmitted mail.<br />

201

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!