27.11.2012 Views

IronPort - advanced configuration guide

IronPort - advanced configuration guide

IronPort - advanced configuration guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 1 Customizing Listeners<br />

Timeouts for SenderBase Queries<br />

OL-25137-01<br />

Note that this parameter relates to the Mail Flow Policy -> Rate Limiting phase. It is not the same<br />

as the “bits” field in the “network/bits” CIDR notation that may be used to classify IP addresses in<br />

a Sender Group.<br />

By default, SenderBase Reputation Filters and IP Profiling support are enabled for public listeners and<br />

disabled for private listeners.<br />

The method by which queries to the SenderBase information service — for both SenderBase DNS<br />

queries and SenderBase Reputation Service Scores (SBRS Scores) — are configured has been improved<br />

beginning with the 4.0 release of AsyncOS. Previously, the configurable timeout value maximum of 5<br />

seconds could cause a delay in mail processing for some Cisco <strong>IronPort</strong> appliances experiencing heavy<br />

load if the SenderBase information services were unreachable or unavailable.<br />

The new timeout value can be configured first by issuing the listenerconfig -> setup command to<br />

change the global settings for caching SenderBase information service data. You can allow the<br />

SenderBase information service to determine the cache time (which is recommended), or you can specify<br />

your own cache time. You can also disable caching.<br />

You enable “look ups” to the SenderBase Information Service in the listenerconfig -> setup<br />

command for listeners.<br />

In this example, the feature is enabled and the default timeout values (for queries and for all queries per<br />

connection) are accepted:<br />

Would you like to enable SenderBase Reputation Filters and IP Profiling<br />

support? [Y]> y<br />

Enter a timeout, in seconds, for SenderBase queries. Enter '0' to<br />

disable SenderBase Reputation Filters and IP Profiling.<br />

[5]><br />

Enter a timeout, in seconds, for all SenderBase queries per connection.<br />

[20]><br />

Then, for each mail flow policy, you allow “look ups” to the SenderBase Information service on a<br />

per-mail flow policy basis using the listenerconfig -> hostaccess -> edit command:<br />

Would you like to use SenderBase for flow control by default? (Yes/No/Default) [Y]><br />

In the GUI:<br />

Cisco <strong>IronPort</strong> AsyncOS 7.6 for Email Advanced Configuration Guide<br />

1-17

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!