27.11.2012 Views

IronPort - Configuration Guide - AsyncOS 7.6.1

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 9 Anti-Spam<br />

Cisco <strong>IronPort</strong> Intelligent Multi-Scan Filtering<br />

OL-25136-01<br />

Cisco <strong>IronPort</strong> Intelligent Multi-Scan incorporates multiple anti-spam scanning engines, including<br />

Cisco <strong>IronPort</strong> Anti-Spam, to provide an intelligent, multi-layer anti-spam solution. This method<br />

provides more accurate verdicts that increase the amount of spam that is caught but without increasing<br />

the false positives rate.<br />

When processed by Cisco <strong>IronPort</strong> Intelligent Multi-Scan, a message is first scanned by third-party<br />

anti-spam engines. Cisco <strong>IronPort</strong> Intelligent Multi-Scan then passes the message and the verdicts of the<br />

third-party engines to Cisco <strong>IronPort</strong> Anti-Spam, which assumes responsibility for the final verdict.<br />

After Cisco <strong>IronPort</strong> Anti-Spam performs its scan, it returns a combined multi-scan score to <strong>AsyncOS</strong>.<br />

Combining the benefits of the third-party scanning engines and Cisco <strong>IronPort</strong> Anti-Spam results in<br />

more caught spam while maintaining Cisco <strong>IronPort</strong> Anti-Spam’s low false positive rate.<br />

You cannot configure the order of the scanning engines used in Cisco <strong>IronPort</strong> Intelligent Multi-Scan;<br />

Cisco <strong>IronPort</strong> Anti-Spam will always be the last to scan a message and Cisco <strong>IronPort</strong> Intelligent<br />

Multi-Scan will not skip it if a third-party engine determines that a message is spam.<br />

Using Cisco <strong>IronPort</strong> Intelligent Multi-Scan can lead to reduced system throughput. Please contact your<br />

Cisco <strong>IronPort</strong> support representative for more information.<br />

This feature is supported on all C-Series and X-Series appliances, except for the C100 appliance.<br />

Note The Intelligent Multi-Scan feature key also enables Cisco <strong>IronPort</strong> Anti-Spam on the appliance, giving<br />

you the option of enabling either Cisco <strong>IronPort</strong> Intelligent MultiScan or Cisco <strong>IronPort</strong> Anti-Spam for<br />

a mail policy.<br />

Enabling Cisco <strong>IronPort</strong> Intelligent Multi-Scan and Configuring Global Settings<br />

Overview<br />

You enable Cisco <strong>IronPort</strong>Intelligent Multi-Scan and modify its global configuration settings using the<br />

Security Services > <strong>IronPort</strong> Intelligent Multi-Scan and Security Services > Service Updates pages<br />

(GUI) or the antispamconfig and updateconfig commands (CLI). The following global settings are<br />

configured:<br />

Enable Cisco <strong>IronPort</strong> Intelligent Multi-Scan globally for the appliance.<br />

Configure the maximum size of message to be scanned by Cisco <strong>IronPort</strong> Intelligent Multi-Scan.<br />

Enter a length of time to wait for timeout when scanning a message.<br />

Most users will not need to change the maximum message size to be scanned or the timeout value.<br />

That said, you may be able to optimize the throughput of your appliance by lowering the maximum<br />

message size setting.<br />

Define and (optionally) enable a proxy server for obtaining Cisco <strong>IronPort</strong> Intelligent Multi-Scan<br />

rules updates (Security Services > Service Updates). If you define a proxy server to retrieve rules<br />

updates, you can optionally configure an authenticated username, password, and specific port when<br />

connecting to the proxy server.<br />

Define and (optionally) enable a download server from which to receive Cisco <strong>IronPort</strong> Intelligent<br />

Multi-Scan rules updates (Security Services > Service Updates).<br />

Enable or disable receiving automatic updates to Cisco <strong>IronPort</strong> Intelligent Multi-Scan rules, and<br />

also specify the update interval.<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email <strong>Configuration</strong> <strong>Guide</strong><br />

9-9

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!