27.11.2012 Views

IronPort - advanced configuration guide

IronPort - advanced configuration guide

IronPort - advanced configuration guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

2-74<br />

Cisco <strong>IronPort</strong> AsyncOS 7.6 for Email Advanced Configuration Guide<br />

Chapter 2 Configuring Routing and Delivery Features<br />

Note For outgoing mail, RSA Email Data Loss Prevention scanning takes place after the Outbreak Filters<br />

stage.<br />

Table 2-11 Email Pipeline for the Cisco <strong>IronPort</strong> Appliance: Receiving Email Features<br />

Feature Description<br />

Host Access Table (HAT)<br />

ACCEPT, REJECT, RELAY, or TCPREFUSE<br />

Host DNS Sender Verification connections<br />

Sender Groups<br />

Maximum outbound connections<br />

Envelope Sender Verification Maximum concurrent inbound connections per IP address<br />

Sender Verification Exception Table Maximum message size and messages per connection<br />

Mail Flow Policies<br />

Maximum recipients per message and per hour<br />

TCP listen queue size<br />

TLS: no/preferred/required<br />

SMTP AUTH: no/preferred/required<br />

Drop email with malformed FROM headers<br />

Always accept or reject mail from entries in the Sender<br />

Verification Exception Table.<br />

SenderBase on/off (IP profiling/flow control)<br />

Received Header Adds a received header to accepted email: on/off.<br />

Default Domain Adds default domain for “bare” user addresses.<br />

Bounce Verification Used to verify incoming bounce messages as legitimate.<br />

Domain Map Rewrites the Envelope Recipient for each recipient in a<br />

message that matches a domain in the domain map table.<br />

Recipient Access Table (RAT) (Public listeners only) ACCEPT or REJECT recipients in<br />

RCPT TO plus Custom SMTP Response. Allow special<br />

recipients to bypass throttling.<br />

Alias tables Rewrites the Envelope Recipient. (Configured<br />

system-wide. aliasconfig is not a subcommand of<br />

listenerconfig.)<br />

LDAP Recipient Acceptance LDAP validation for recipient acceptance occurs within<br />

the SMTP conversation. If the recipient is not found in the<br />

LDAP directory, the message is dropped or bounced.<br />

LDAP validation can be configured to occur within the<br />

work queue instead.<br />

OL-25137-01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!