27.11.2012 Views

IronPort - advanced configuration guide

IronPort - advanced configuration guide

IronPort - advanced configuration guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 6 Using Message Filters to Enforce Email Policies<br />

OL-25137-01<br />

Note Unlike the spf-status rule, the spf-passed rule reduces the SPF/SIDF verification values to a simple<br />

Boolean. The following verification results are treated as not passed in the spf-passed rule: None,<br />

Neutral, Softfail, TempError, PermError, and Fail. To perform actions on messages based on more<br />

granular results, use the spf-status rule.<br />

Workqueue-count Rule<br />

The workqueue-count rule checks the workqueue-count against a specified value. All the comparison<br />

operators are allowed, such as >, ==, 1000) {<br />

}<br />

skip-spamcheck();<br />

For more information on SPF/SIDF, see Overview of SPF and SIDF Verification, page 5-22.<br />

SMTP Authenticated User Match Rule<br />

If your Cisco <strong>IronPort</strong> appliance uses SMTP authentication to send messages, the<br />

smtp-auth-id-matches ( [, ])rule can check a message’s headers and Envelope<br />

Sender against the sender’s SMTP authenticated user ID to identify outgoing messages with spoofed<br />

headers. This filter allows the system to quarantine or block potentially spoofed messages.<br />

The smtp-auth-id-matches rule compares the SMTP authenticated ID against the following targets:<br />

Target Description<br />

*EnvelopeFrom Compares the address of the Envelope Sender (also known<br />

as MAIL FROM) in the SMTP conversation<br />

*FromAddress Compares the addresses parsed out of the From header.<br />

Since multiple addresses are permitted in the From:<br />

header, only one has to match.<br />

*Sender Compares the address specified in the Sender header.<br />

*Any Matches messages that were created during an<br />

authenticated SMTP session regardless of identity.<br />

*None Matches messages that were not created during an<br />

authenticated SMTP session. This is useful when<br />

authentication is optional (preferred).<br />

The filter performs matches loosely. It is not case-sensitive. If the optional sieve-char parameter is<br />

supplied, the last portion of an address that follows the specified character will be ignored for the<br />

purposes of comparison. For example, if the + character is included as a parameter, the filter ignores the<br />

portion of the address joe+folder@example.com that follows the + character. If the address was<br />

Cisco <strong>IronPort</strong> AsyncOS 7.6 for Email Advanced Configuration Guide<br />

6-37

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!