27.11.2012 Views

IronPort - advanced configuration guide

IronPort - advanced configuration guide

IronPort - advanced configuration guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 5 Email Authentication<br />

OL-25137-01<br />

The following SPF control settings are available for the Host Access Table:<br />

Table 5-2 SPF Control Settings via the CLI<br />

Conformance Level Available SPF Control Settings<br />

SPF Only whether to perform HELO identity check<br />

SMTP actions taken based on the results of the<br />

following identity checks:<br />

– HELO identity (if enabled)<br />

– MAIL FROM Identity<br />

SMTP response code and text returned for the REJECT<br />

action<br />

SIDF Compatible<br />

verification time out (in seconds)<br />

whether to perform a HELO identity check<br />

whether the verification downgrades a Pass result of the<br />

PRA identity to None if the Resent-Sender: or<br />

Resent-From: headers are present in the message<br />

SMTP actions taken based on the results of the<br />

following identity checks:<br />

– HELO identity (if enabled)<br />

– MAIL FROM Identity<br />

– PRA Identity<br />

SMTP response code and text returned for the REJECT<br />

action<br />

SIDF Strict<br />

verification timeout (in seconds)<br />

SMTP actions taken based on the results of the<br />

following identity checks:<br />

– MAIL FROM Identity<br />

– PRA Identity<br />

The following example shows a user configuring the SPF/SIDF verification using the SPF Only<br />

conformance level. The appliance performs the HELO identity check and accepts the None and Neutral<br />

verification results and rejects the others. The CLI prompts for the SMTP actions are the same for all<br />

identity types. The user does not define the SMTP actions for the MAIL FROM identity. The appliance<br />

automatically accepts all verification results for the identity. The appliance uses the default reject code<br />

and text for all REJECT results.<br />

Would you like to change SPF/SIDF settings? [N]> yes<br />

SMTP response code and text returned in case of SPF<br />

REJECT action<br />

verification timeout (in seconds)<br />

Would you like to perform SPF/SIDF Verification? [N]> yes<br />

Cisco <strong>IronPort</strong> AsyncOS 7.6 for Email Advanced Configuration Guide<br />

5-27

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!