27.11.2012 Views

IronPort - Configuration Guide - AsyncOS 7.6.1

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

4-2<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email <strong>Configuration</strong> <strong>Guide</strong><br />

Chapter 4 Understanding the Email Pipeline<br />

Shaded areas in Table 4-2 represent processing that occurs in the Work Queue (see Work Queue /<br />

Routing, page 4-6). You can test most of the configurations of features in this pipeline using the trace<br />

command. For more information, seeDebugging Mail Flow Using Test Messages: Trace, page -446.<br />

Table 4-1 Email Pipeline for the Cisco <strong>IronPort</strong> Appliance: Receiving Email Features<br />

Feature Description<br />

Host Access Table (HAT)<br />

Host DNS Sender Verification<br />

Sender Groups<br />

Envelope Sender Verification<br />

Sender Verification Exception Table<br />

Mail Flow Policies<br />

ACCEPT, REJECT, RELAY, or TCPREFUSE connections<br />

Maximum outbound connections<br />

Maximum concurrent inbound connections per IP address<br />

Maximum message size and messages per connection<br />

Maximum recipients per message and per hour<br />

TCP listen queue size<br />

TLS: no/preferred/required<br />

SMTP AUTH: no/preferred/required<br />

Drop email with malformed FROM headers<br />

Always accept or reject mail from entries in the Sender<br />

Verification Exception Table.<br />

Received Header<br />

SenderBase on/off (IP profiling/flow control)<br />

Adds a received header to accepted email: on/off.<br />

Default Domain Adds default domain for “bare” user addresses.<br />

Bounce Verification Used to verify incoming bounce messages as legitimate.<br />

Domain Map Rewrites the Envelope Recipient for each recipient in a<br />

message that matches a domain in the domain map table.<br />

Recipient Access Table (RAT) (Public listeners only) ACCEPT or REJECT recipients in RCPT<br />

TO plus Custom SMTP Response. Allow special recipients to<br />

bypass throttling.<br />

Alias tables Rewrites the Envelope Recipient. (Configured system-wide.<br />

aliasconfig is not a subcommand of listenerconfig.)<br />

LDAP Recipient Acceptance LDAP validation for recipient acceptance occurs within the<br />

SMTP conversation. If the recipient is not found in the LDAP<br />

directory, the message is dropped or bounced. LDAP validation<br />

can be configured to occur within the work queue instead.<br />

SMTP Call-Ahead Validation SMTP call-ahead recipient validation occurs within the SMTP<br />

conversation. The SMTP conversation is paused while the<br />

Email Security appliance calls ahead to the external SMTP<br />

server. The message is dropped or bounced, or the mailing<br />

action is allowed depending on the SMTP server response.<br />

OL-25136-01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!