26.11.2012 Views

IronPort - CLI reference guide

IronPort - CLI reference guide

IronPort - CLI reference guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter<br />

Step 2 Outside of the Command Line Interface (<strong>CLI</strong>), get the file inbound.HAT.txt.<br />

Step 3 With a text editor, create new HAT entries in the file.<br />

In this example, the following entries are added to the HAT above the ALL<br />

entry:<br />

spamdomain.com REJECT<br />

.spamdomain.com REJECT<br />

251.192.1. TCPREFUSE<br />

169.254.10.10 RELAY<br />

– The first two entries reject all connections from the remote hosts in the<br />

domain spamdomain.com and any subdomain of spamdomain.com.<br />

– The third line refuses connections from any host with an IP address of<br />

251.192.1.x.<br />

– The fourth line allows the remote host with the IP address of<br />

169.254.10.10 to use the <strong>IronPort</strong> appliance as an SMTP relay for all of<br />

its outbound email to the Internet<br />

Note The order that rules appear in the HAT is important. The HAT is read from<br />

top to bottom for each host that attempts to connect to the listener. If a rule<br />

matches a connecting host, the action is taken for that connection<br />

immediately. You should place all custom entries in the HAT above an<br />

ALL host definition. You can also use the HAT <strong>CLI</strong> editor or the GUI to<br />

customize the HAT for a listener. For more information, see the<br />

“Configuring the Gateway to Receive Mail” and “Using Mail Flow<br />

Monitor” chapters in the <strong>IronPort</strong> AsyncOS User Guide.<br />

Step 4 Save the file and place it in the configuration directory for the interface so that it<br />

can be imported. (See Appendix B, “Accessing the Appliance,” for more<br />

information.)<br />

Step 5 Use the hostaccess -> import subcommand of listenerconfig to import the<br />

edited Host Access Table file.<br />

Cisco <strong>IronPort</strong> AsyncOS 7.6 <strong>CLI</strong> Reference Guide<br />

511

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!