27.11.2012 Views

IronPort - advanced configuration guide

IronPort - advanced configuration guide

IronPort - advanced configuration guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 6 Using Message Filters to Enforce Email Policies<br />

OL-25137-01<br />

Similarly, if you have multiple attachments, AsyncOS totals the scores for each attachment to determine<br />

the score for matches. For example, you have an attachment-contains filter rule with a threshold of 3.<br />

You receive a message with two attachments, and each attachment contains two matches. AsyncOS<br />

would score this message with four matches and determine that the threshold score has been met.<br />

Threshold Scoring Multipart/Alternative MIME Parts<br />

To avoid duplicate counting, if there are two representatives of the same content (plain text and HTML),<br />

AsyncOS does not total the matches from the duplicate parts. Instead, it compares the matches in each<br />

part and selects the highest value. AsyncOS would then add this value to the scores from other parts of<br />

the multipart message to create a total score.<br />

For example, you configure a body-contains filter rule and set the threshold to 4. You then receive a<br />

message that contains both plain text, HTML and two attachments. The message would use the<br />

following structure:<br />

multipart/mixed<br />

The body-contains filter rule would determine the score for this message by first scoring the text/plain<br />

and text/html parts of the message. It would then compare the results of these scores and select the<br />

highest score from the results. Next, it would add this result to the score from each of the attachments to<br />

determine the final score. Suppose the message has the following number of matches:<br />

multipart/mixed<br />

multipart/alternative<br />

text/plain<br />

text/html<br />

application/octet-stream<br />

application/octet-stream<br />

multipart/alternative<br />

text/plain (2 matches)<br />

text/html (2 matches)<br />

application/octet-stream (1 match)<br />

application/octet-stream<br />

Because AsyncOS compares the matches for the text/plain and text/html parts, it returns a score of 3,<br />

which does not meet the minimum threshold to trigger the filter rule.<br />

Threshold Scoring for Content Dictionaries<br />

When you use a content dictionary, you can “weight” terms so that certain terms trigger filter actions<br />

more easily. For example, you may want not want to trigger a message filter for the term, “bank.”<br />

However, if the term, “bank” is combined with the term, “account,” and accompanied with an ABA<br />

Cisco <strong>IronPort</strong> AsyncOS 7.6 for Email Advanced Configuration Guide<br />

6-7

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!