27.11.2012 Views

IronPort - daily management guide - AsyncOS 7.6.1

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

OL-25138-01<br />

Using Email Security Monitor<br />

CHAPTER<br />

2<br />

The Email Security Monitor feature on the Cisco <strong>IronPort</strong> appliance is a powerful, web-based console<br />

that provides complete visibility into all inbound email traffic for your enterprise.<br />

The Email Security Monitor feature integrates tightly into the system, collecting data from every step in<br />

the email delivery process, including reputation filtering, anti-spam, anti-virus scanning, Outbreak<br />

Filters, policy enforcement (including content filters and data loss prevention), and message delivery.<br />

The database identifies and records each email sender by IP address, while interfacing with the<br />

SenderBase Reputation Service for real-time identity information. You can instantly report on any email<br />

sender’s local mail flow history and show a profile that includes the sender’s global record on the<br />

Internet. The Email Security Monitor feature allows your security team to “close the loop” on who is<br />

sending mail to your users, the amount of mail sent from and received by your users, and the<br />

effectiveness of your security policies.<br />

This chapter explains how to:<br />

Access the Email Security Monitor feature to monitor inbound and outbound message flow.<br />

Make mail flow policy decisions (update whitelists, blacklists, and greylists) by querying for a<br />

sender’s SenderBase Reputation Score (SBRS). You can query on network owners, domains, and<br />

even individual IP addresses.<br />

Report on mail flow, system status, and mail sent to and from your network.<br />

This chapter contains the following sections:<br />

Email Security Monitor Overview, page 2-1<br />

Email Security Monitor Pages, page 2-2<br />

Reporting Overview, page 2-43<br />

Managing Reports, page 2-44<br />

Email Security Monitor Overview<br />

For any given email sender for incoming mail, the Email Security Monitor database captures critical<br />

parameters such as:<br />

Message volume<br />

Connection history<br />

Accepted vs. rejected connections<br />

Acceptance rates and throttle limits<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email Daily Management Guide<br />

2-1

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!