27.11.2012 Views

IronPort - daily management guide - AsyncOS 7.6.1

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Email Security Monitor Pages<br />

2-6<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email Daily Management Guide<br />

Chapter 2 Using Email Security Monitor<br />

While the mail trend graph displays a visual representation of the mail flow, the summary table (right<br />

side, Figure 2-2) provides a numeric breakdown of the same information. The summary table includes<br />

the percentage and actual number of each type of message, including the total number of attempted,<br />

threat, and clean messages.<br />

The outgoing graph and summary show similar information for outbound mail.<br />

Notes on Counting Messages in Email Security Monitor<br />

Categorizing Email<br />

The method Email Security Monitor uses to count incoming mail depends on the number of recipients<br />

per message. For example, an incoming message from example.com sent to three recipients would count<br />

as three messages coming from that sender.<br />

Because messages blocked by reputation filtering do not actually enter the work queue, the appliance<br />

does not have access to the list of recipients for an incoming message. In this case, a multiplier is used<br />

to estimate the number of recipients. This multiplier was determined by Cisco and based upon research<br />

of a large sampling of existing customer data.<br />

Figure 2-2 The Incoming Mail Graph and Summary Table<br />

Messages reported in the Overview and Incoming Mail pages are categorized as follows:<br />

Stopped by Reputation Filtering: All connections blocked by HAT policies multiplied by a fixed<br />

multiplier (see Notes on Counting Messages in Email Security Monitor, page 2-6) plus all recipients<br />

blocked by recipient throttling.<br />

Invalid Recipients: All recipients rejected by conversational LDAP rejection plus all RAT rejections.<br />

Spam Messages Detected: The total count of messages detected by the anti-spam scanning engine as<br />

positive or suspect and also those that were both spam and virus positive.<br />

Virus Messages Detected: The total count and percentage of messages detected as virus positive and<br />

not also spam.<br />

OL-25138-01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!