27.11.2012 Views

IronPort - advanced configuration guide

IronPort - advanced configuration guide

IronPort - advanced configuration guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 3 LDAP Queries<br />

OL-25137-01<br />

For example, you are prompted with these questions when creating or editing a mail flow policy in a<br />

public listener’s HAT in the CLI — the listenerconfig -> edit -> hostaccess -> default | new<br />

commands:<br />

Do you want to enable Directory Harvest Attack Prevention per host? [Y]> y<br />

Enter the maximum number of invalid recipients per hour from a remote host.<br />

[25]><br />

This feature is also displayed when editing any mail flow policy in the GUI, providing that LDAP queries<br />

have been configured on the corresponding listener:<br />

Figure 3-15 DHAP Prevention Feature in GUI<br />

Entering a number of invalid recipients per hour enables DHAP for that mail flow policy. By default, 25<br />

invalid recipients per hour are allowed for public listeners. For private listeners, the maximum invalid<br />

recipients per hour is unlimited by default. Setting it to “Unlimited” means that DHAP is not enabled for<br />

that mail flow policy.<br />

Configuring AsyncOS for SMTP Authentication<br />

AsyncOS provides support for SMTP authentication. SMTP Auth is a mechanism for authenticating<br />

clients connected to an SMTP server.<br />

The practical use of this mechanism is that users at a given organization are able to send mail using that<br />

entity’s mail servers even if they are connecting remotely (e.g. from home or while traveling). Mail User<br />

Agents (MUAs) can issue an authentication request (challenge/response) when attempting to send a<br />

piece of mail.<br />

Users can also use SMTP authentication for outgoing mail relays. This allows the Cisco <strong>IronPort</strong><br />

appliance to make a secure connection to a relay server in <strong>configuration</strong>s where the appliance is not at<br />

the edge of the network.<br />

AsyncOS complies with RFC 2554 which defines how an authentication command may be given in an<br />

SMTP conversation, the responses to the negotiation, and any error codes that may need to be generated.<br />

AsyncOS supports two methods to authenticate user credentials:<br />

You can use an LDAP directory.<br />

You can use a different SMTP server (SMTP Auth forwarding and SMTP Auth outgoing).<br />

Cisco <strong>IronPort</strong> AsyncOS 7.6 for Email Advanced Configuration Guide<br />

3-31

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!