12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

60 Understanding accessProxiesTable 4-6CodeDescriptionSMTP return codes (Continued)452 The command was aborted due to insufficient system storage.500 The server could not recognize the command due to syntax error.501 A syntax error was encountered in command arguments.502 This command is not implemented.503 The server has encountered a bad sequence of commands.504 A command parameter is not implemented.550 The requested command failed because the user’s mailbox was unavailable.551 The recipient is not local to the server.552 The action was aborted due to exceeded storage allocation.553 The command was aborted because the mailbox name is invalid.554 The transaction failed.Hard and soft limitsThe SMTP proxy lets the administrator set hard and soft limits for recipients in email messages. Thisfeature is used to help the proxy prevent against mail spamming.A soft limit sets the maximum number of recipients in an email header that are accepted at one time. If thenumber of recipients exceeds the soft limit, the first group of recipients, equal to the soft limit, is sent out.The SMTP proxy then sends a 452 error back to the SMTP server. It is up to the server how it deals with theerror. Generally, the SMTP server resends the email with a modified list of recipients that no longerincludes the addresses that were already successfully sent. The effect a soft limit has is to throttle theSMTP proxy, sending emails out in small batches of recipients instead of flooding a large number ofrecipients all at once.A hard limit defines a maximum number of recipients permitted in an email message header. An email sentwith a number of recipients larger than this hard limit is blocked, and a corresponding code is sent backtelling the SMTP server that the SMTP proxy denied the message. Again, it is up to the SMTP server how ithandles the response from the SMTP proxy. Hard limits should be used to prevent spamming or to limit thesize of company mailings. The soft limit takes precedence when both the soft limit and hard limits are set.Note: An SMTP server may not define the number of recipients in the header, but instead, embed thenumber in the message. You should enforce hard limits at the SMTP server.The Telnet proxySimilar to most of the other proxies, the Telnet proxy performs forward and reverse lookups on the sourceIP address of the connection attempt. If the results of the lookups are not consistent, the proxy suspectsDNS contamination and drops the connection.If the Telnet proxy accepts the lookup information and the connection is non-transparent, the Telnet proxyprompts the client for the destination host name and (optionally) the destination port. For transparentconnections, the destination is already known. When this information is provided, gwcontrol:■■■Denies the connection if the destination host name does not exist or is invalidAllows the connection without restrictionsAllows the connection with user, group, or authentication restrictions

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!