27.11.2012 Views

IronPort - advanced configuration guide

IronPort - advanced configuration guide

IronPort - advanced configuration guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 2 Configuring Routing and Delivery Features<br />

Figure 2-14 Setting Destination and Delivery Parameters<br />

Using Virtual Gateway Technology<br />

OL-25137-01<br />

Public Listener: InboundMail<br />

Host Access Table (HAT):<br />

WHITELIST: $TRUSTED<br />

BLACKLIST: $BLOCKED<br />

SUSPECTLIST: $THROTTLED<br />

UNKNOWNLIST: $ACCEPTED<br />

spamdomain.com REJECT<br />

.spamdomain.com REJECT<br />

251.192.1. TCPREFUSE<br />

169.254.10.10 RELAY<br />

ALL: $ACCEPTED<br />

Recipient Access Table (RAT):<br />

example.com ACCEPT<br />

newcompanyname.com ACCEPT<br />

ALL REJECT<br />

IP interface: PublicNet (e.g. 192.168.2.1)<br />

Ethernet interface: Data 2<br />

Ethernet interface: Data 1<br />

IP interface: PrivateNet (e.g. 192.168.1.1)<br />

Private Listener: OutboundMail<br />

Host Access Table (HAT):<br />

RELAYLIST: $RELAYED<br />

ALL: $BLOCKED<br />

Default sender domain: example.com<br />

Received: header: DISABLED<br />

Masquerading:<br />

<strong>IronPort</strong> Email<br />

Security appliance<br />

A destconfig entry for the host<br />

small-isp.net was used to limit<br />

100 simultaneous connections, or<br />

10 simultaneous connections using<br />

Virtual Gateway addresses.<br />

The deliveryconfig command<br />

was used to use Auto-selection of<br />

interfaces for email delivery and<br />

the Possible Delivery feature was<br />

enabled. The system-wide<br />

maximum outbound message<br />

delivery was set to 9000 total<br />

concurrent connections.<br />

This section describes Cisco <strong>IronPort</strong> Virtual Gateway technology and its benefits, how to set up a<br />

Virtual Gateway address, and how to monitor and manage Virtual Gateway addresses.<br />

The Cisco <strong>IronPort</strong> Virtual Gateway technology allows you to configure enterprise mail gateways for all<br />

domains you host — with distinct IP addresses, hostname and domains — and create separate corporate<br />

email policy enforcement and anti-spam strategies for those domains, while hosted within the same<br />

physical appliance.<br />

Cisco <strong>IronPort</strong> AsyncOS 7.6 for Email Advanced Configuration Guide<br />

2-59

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!