The administrator should therefore add a reasonable margin
above the anticipated email size when setting this limit.
Email address blacklisting
A blacklist of sender or recipient email addresses can be
specified so that mail from/to those addresses is blocked. The
blacklist is applied after the whitelist so that if an address
matches a whitelist entry it is not then checked against the
blacklist.
Email address whitelisting
A whitelist of email addresses can be specified so that any
mail from/to those addresses is allowed to pass through the
ALG regardless if the address is on the blacklist or that the
mail has been flagged as Spam.
Verify MIME type
The content of an attached file can be checked to see if it
agrees with its stated filetype. A list of all filetypes that are
verified in this way can be found in Appendix C, Verified
MIME filetypes. This same option is also available in the
HTTP ALG and a fuller description of how it works can be
found in Section 6.2.2, “The HTTP ALG”.
Block/Allow filetype
Filetypes from a predefined list can optionally be blocked or
allowed as mail attachments and new filetypes can be added
to the list. This same option is also available in the HTTP
ALG and a fuller description of how it works can be found in
Section 6.2.2, “The HTTP ALG”. This same option is also
available in the HTTP ALG and a fuller description of how it
works can be found in Section 6.2.2, “The HTTP ALG”.
Anti-Virus scanning
The NetDefendOS Anti-Virus subsystem can scan email
attachments searching for malicious code. Suspect files can
be dropped or just logged. This feature is common to a
number of ALGs and is described fully in Section 6.4,
“Anti-Virus Scanning”.
The Ordering for SMTP Filtering
SMTP filtering obeys the following processing order and is similar to the order followed by the
HTTP ALG except for the addition of Spam filtering:
1.
Whitelist.
2.
Blacklist.
3.
Spam filtering (if enabled).
4.
Anti-virus scanning (if enabled).
As described above, if an address is found on the whitelist then it will not be blocked if it also found
on the blacklist. Spam filtering, if it is enabled, is still applied to whitelisted addresses but emails
flagged as Spam will not be tagged nor dropped, only logged. Anti-virus scanning, if it is enabled, is
always applied, even though an email's address is whitelisted.
Notice that either an email's sender or receiver address can be the basis for blocking by one of the
first two filtering stages.
6.2.5. The SMTP ALG
Chapter 6. Security Mechanisms
260
Summary of Contents for NetDefend DFL-260E
Page 27: ...1 3 NetDefendOS State Engine Packet Flow Chapter 1 NetDefendOS Overview 27...
Page 79: ...2 7 3 Restore to Factory Defaults Chapter 2 Management and Maintenance 79...
Page 146: ...3 9 DNS Chapter 3 Fundamentals 146...
Page 227: ...4 7 5 Advanced Settings for Transparent Mode Chapter 4 Routing 227...
Page 241: ...5 4 IP Pools Chapter 5 DHCP Services 241...
Page 339: ...6 7 Blacklisting Hosts and Networks Chapter 6 Security Mechanisms 339...
Page 360: ...7 4 7 SAT and FwdFast Rules Chapter 7 Address Translation 360...
Page 382: ...8 3 Customizing HTML Pages Chapter 8 User Authentication 382...
Page 386: ...The TLS ALG 9 1 5 The TLS Alternative for VPN Chapter 9 VPN 386...
Page 439: ...Figure 9 3 PPTP Client Usage 9 5 4 PPTP L2TP Clients Chapter 9 VPN 439...
Page 450: ...9 7 6 Specific Symptoms Chapter 9 VPN 450...
Page 488: ...10 4 6 Setting Up SLB_SAT Rules Chapter 10 Traffic Management 488...
Page 503: ...11 6 HA Advanced Settings Chapter 11 High Availability 503...
Page 510: ...12 3 5 Limitations Chapter 12 ZoneDefense 510...
Page 533: ...13 9 Miscellaneous Settings Chapter 13 Advanced Settings 533...