27.11.2012 Views

IronPort - Configuration Guide - AsyncOS 7.6.1

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring Reputation Filtering<br />

Conservative<br />

Moderate<br />

Aggressive<br />

7-6<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email <strong>Configuration</strong> <strong>Guide</strong><br />

Chapter 7 Reputation Filtering<br />

Configure reputation filtering via the Mail Policies > HAT Overview page. For more information, see<br />

Implementing SenderBase Reputation Filters, page 7-4.<br />

A conservative approach is to block messages with a SenderBase Reputation Score lower than -4.0,<br />

throttle between -4.0 and -2.0, apply the default policy between -2.0 and +6.0, and apply the trusted<br />

policy for messages with a score greater than +6.0. Using this approach ensures a near zero false positive<br />

rate while achieving better system performance.<br />

A moderate approach is to block messages with a SenderBase Reputation Score lower than -3.0, throttle<br />

between -3.0 and 0, apply the default policy between 0 and +6.0, and apply the trusted policy for<br />

messages with a score greater than +6.0. Using this approach ensures a very small false positive rate<br />

while achieving better system performance (because more mail is shunted away from Anti-Spam<br />

processing).<br />

An aggressive approach is to block messages with a SenderBase Reputation Score lower than -2.0,<br />

throttle between -2.0 and 0.5, apply the default policy between 0 and +4.0, and apply the trusted policy<br />

for messages with a score greater than +4.0. Using this approach, you might incur some false positives;<br />

however, this approach maximizes system performance by shunting the most mail away from Anti-Spam<br />

processing.<br />

Note Users are also recommended to assign all messages with a SenderBase Reputation Score greater than 6.0<br />

to the $TRUSTED policy.<br />

Table 7-2 Recommended Phased Approach to Implementing Reputation Filtering using the<br />

SBRS<br />

Policy Blacklist Throttle Default Whitelist<br />

Conservative -10 to -4 -4 to -2 -2 to 7 7 to 10<br />

Moderate -10 to -3 -3 to -1 -1 to 6 6 to 10<br />

Aggressive -10 to -2 -2 to -0.5 -0.5 to 4 4 to 10<br />

Policy: Characteristics: Mail Flow Policy to Apply:<br />

Conservative: Near zero false positives, better performance $BLOCKED<br />

Moderate: Very few false positives, high performance $THROTTLED<br />

Aggressive: Some false positives, maximum performance $DEFAULT<br />

The steps below outline a phased approach to implementing reputation filtering:<br />

OL-25136-01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!