27.11.2012 Views

IronPort - Configuration Guide - AsyncOS 7.6.1

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

1-12<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email <strong>Configuration</strong> <strong>Guide</strong><br />

Chapter 1 Getting Started with the Cisco <strong>IronPort</strong> Email Security Appliance<br />

Email Authentication. Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> supports various forms of email authentication,<br />

including Sender Policy Framework (SPF), Sender ID Framework (SIDF), and DomainKeys<br />

Identified Mail (DKIM) verification of incoming mail, as well as DomainKeys and DKIM signing<br />

of outgoing mail.<br />

Cisco <strong>IronPort</strong> Email Encryption. You can encrypt outgoing mail to address HIPAA, GLBA and<br />

similar regulatory mandates. To do this, you configure an encryption policy on the Email Security<br />

appliance and use a local key server or hosted key service to encrypt the message.<br />

Email Security Manager, a single, comprehensive dashboard to manage all email security services<br />

and applications on the appliance. Email Security Manager can enforce email security based on user<br />

groups, allowing you to manage Cisco <strong>IronPort</strong> Reputation Filters, Outbreak Filters, Anti-Spam,<br />

Anti-Virus, and email content policies through distinct inbound and outbound policies.<br />

On-box Quarantine areas to hold messages that violate email policies. Quarantines seamlessly<br />

interact with the Outbreak Filters feature.<br />

On-box message tracking. <strong>AsyncOS</strong> for Email includes an on-box message tracking feature that<br />

makes it easy to find the status of messages that the Email Security appliance processes.<br />

Mail Flow Monitoring of all inbound and outbound email that provides complete visibility into all<br />

email traffic for your enterprise.<br />

Access control for inbound senders, based upon the sender’s IP address, IP address range, or<br />

domain.<br />

Extensive message filtering technology allows you to enforce corporate policy and act on specific<br />

messages as they enter or leave your corporate infrastructure. Filter rules identify messages based<br />

on message or attachment content, information about the network, message envelope, message<br />

headers, or message body. Filter actions allow messages to be dropped, bounced, archived, blind<br />

carbon copied, or altered, or to generate notifications.<br />

Message encryption via secure SMTP over Transport Layer Security ensures messages<br />

travelling between your corporate infrastructure and other trusted hosts are encrypted.<br />

Virtual Gateway technology allows the Cisco <strong>IronPort</strong> appliance to function as several email<br />

gateways within a single server, which allows you to partition email from different sources or<br />

campaigns to be sent over separate IP addresses. This ensures that deliverability issues affecting one<br />

IP address do not impact others.<br />

<strong>AsyncOS</strong> for Email is a proprietary operating system that has been highly optimized for the task of<br />

Internet messaging. <strong>AsyncOS</strong> is a “hardened” operating system: all unnecessary services have been<br />

removed, which increases security and optimizes system performance. Cisco <strong>IronPort</strong> stackless<br />

threading technology eliminates allocation of a dedicated memory stack to each task, which increases<br />

concurrency and stability of the MTA. The custom I/O-driven scheduler is optimized for massively<br />

concurrent I/O events required by the email gateway versus the preemptive time slicing of the CPU in<br />

traditional operating systems. AsyncFS, the file system underlying <strong>AsyncOS</strong>, is optimized for millions<br />

of small files and ensures data recoverability in the case of system failure.<br />

<strong>AsyncOS</strong> for email supports RFC 2821-compliant Simple Mail Transfer Protocol (SMTP) to accept and<br />

deliver messages. The Cisco <strong>IronPort</strong> appliance is designed to be easy to configure and manage. Most<br />

reporting, monitoring, and configuration commands are available through both the web-based GUI via<br />

HTTP or HTTPS. In addition, an interactive Command Line Interface (CLI) which you access from a<br />

Secure Shell (SSH), telnet, or direct serial connection is provided for the system. The Cisco <strong>IronPort</strong><br />

appliance also features a robust logging capability, allowing you to configure log subscriptions spanning<br />

the functionality of the entire system and reducing the time spent finding the information you need.<br />

OL-26342-01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!