27.11.2012 Views

IronPort - daily management guide - AsyncOS 7.6.1

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Email Security Monitor Pages<br />

2-2<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email Daily Management Guide<br />

Chapter 2 Using Email Security Monitor<br />

Reputation filter matches<br />

Number of anti-spam messages for suspected spam and positively identified spam<br />

Number of virus-positive message detected by anti-virus scanning<br />

See the “Anti-Spam” chapter in the Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> Configuration Guide for more information<br />

on Anti-Spam scanning and the “Anti-Virus” chapter in the Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> Configuration<br />

Guide for more information on anti-virus scanning.<br />

The Email Security Monitor feature also captures information on which content filter a particular<br />

message triggers, including the internal user (email recipient) to or from which the message was sent.<br />

The Email Security Monitor feature is available in the GUI only, and provides a view into your email<br />

traffic and the status of your Cisco <strong>IronPort</strong> appliance (including quarantines, work queues, and<br />

outbreaks). The appliance identifies when a sender falls outside of the normal traffic profile. Senders that<br />

do are highlighted in the interface, allowing you to take corrective action by assigning that sender to a<br />

sender group or refining the access profile of the sender; or, you can let <strong>AsyncOS</strong>’s security services<br />

continue to react and respond. Outbound mail has a similar monitoring capability, providing you a view<br />

into the top domains in the mail queue and the status of receiving hosts (see Delivery Status Details Page,<br />

page 2-20).<br />

Note Information for messages present in the work queue when the appliance is rebooted is not reported by<br />

the Email Security Monitor feature.<br />

Email Security Monitor and Centralized Management<br />

In this version of <strong>AsyncOS</strong>, you cannot aggregate Email Security Monitor reports of clustered Cisco<br />

<strong>IronPort</strong> appliances. All reports are restricted to machine level. This means they cannot be run at the<br />

group or cluster levels — only on individual machines.<br />

The same is true of the Archived Reports page — each machine in effect has its own archive. Thus, the<br />

“Generate Report” feature runs on the selected machine.<br />

The Scheduled Reports page is not restricted to machine level; therefore, settings can be shared across<br />

multiple machines. Individual scheduled reports run at machine level just like interactive reports, so if<br />

you configure your scheduled reports at cluster level, every machine in the cluster will send its own<br />

report.<br />

The “Preview This Report” button always runs against the login-host.<br />

Email Security Monitor Pages<br />

The Email Security Monitor feature is the first page displayed after you access the GUI. To view the<br />

Email Security Monitor feature, access the GUI. (See the “Overview” chapter in the Cisco <strong>IronPort</strong><br />

<strong>AsyncOS</strong> for Email Configuration Guide.) The Overview page on the Monitor menu is displayed. If you<br />

have completed the System Setup Wizard (or the CLI systemsetup command) and committed the<br />

changes, at least one public listener should already be configured to accept email on your appliance. If<br />

the appliance is accepting email, the Overview page will be populated with data.<br />

The Email Security Monitor feature is comprised of all the pages available on the Monitor menu except<br />

the Quarantines pages.<br />

OL-25138-01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!