freeGuard 100 CLI User Manual
229
smtp_spam_emailblack The
spam filter email address list
marked a message as spam.
text
8bit
smtp_spam_mimeheader
The spam MIME headers list marked
a message as spam.
text
8bit
reversedns
Spam filtering return-email DNS
check identified a message as spam.
text
8bit
smtp_spam_bannedword
The spam filter email address list
marked an SMTP message as spam.
text
8bit
Replacement messages can include replacement message tags. When users receive the replacement
message, the replacement message tag is replaced with content relevant to the message.
Replacement message tags
Tag
Description
%%FILE%%
The name of a file that has been removed from a content stream. This
could be a file that contained a virus or was blocked by antivirus file
blocking. %%FILE%% can be used in virus and file block messages.
%%VIRUS%%
The name of a virus that was found in a file by the antivirus system.
%%VIRUS%% can be used in virus messages
%%URL%%
The URL of a web page. This can be a web page that is blocked by
web filter content or URL blocking.
%%URL%%
can also be used in http virus and file block messages to be the URL of
the web page from which a user attempted to download a file that
isblocked.
%%CRITICAL_EVENT%%
Added to alert email critical event email messages.
%%CRITICAL_EVENT%% is replaced with the critical event message
that triggered the alert email.
%%PROTOCOL%%
The protocol (HTTP, FTP, POP3, IMAP, SMTP) in which a virus was
detected. %%PROTOCOL%% is added to alert email virus messages.
%%SOURCE_IP%%
The IP address from which a virus was received. For email this is the IP
address of the email server that sent the email containing the virus. For
HTTP this is the IP address of the web page that sent the virus.
%%DEST_IP%%
The IP address of the computer that would have received the blocked
file. For emailthis is the IP address of the user’s computer that
attempted to download the messagefrom which the file was removed.
%%EMAIL_FROM%%
The email address of the sender of the message from which the file
was removed.
%%EMAIL_TO%%
The email address of the intended receiver of the message from which
the file was removed.
%%NIDS_EVENT%%
The IPS attack message. %%NIDS_EVENT%% is added to alert email
intrusion messages.
Summary of Contents for freeGuard 100
Page 1: ...freeGuard 100 UTM Firewall CLI USER S MANUAL P N F0025000 Rev 1 1...
Page 3: ......
Page 7: ......
Page 87: ...80 The config ips anomaly command has 1 subcommand config limit...
Page 183: ...176...