Previous Topic

Next Topic

Book Contents

Book Index

Using VStream Antispam

ProductBar EMPTYLinked Diagram TemplateLinked Diagram TemplateLinked Diagram TemplateLinked Diagram TemplateProductBar EMPTY

The UTM-1 appliance includes VStream Antispam, an embedded antispam engine that scans emails for spam. VStream Antispam is composed three antispam engines, each of which can be enabled or disabled separately:

Note: If you have a mail server in your network, it is recommended to enable the IP Reputation engine as a first line of defense for incoming SMTP connections. When enabled, the IP Reputation engine blocks emails that would otherwise reach your mail server and require extensive analysis by the Content Based Antispam and Block List engines, both of which examine email content and consume network, gateway, and mail server resources. By reducing the amount of emails that require in-depth analysis, the IP Reputation engine helps prevent Denial of Service (DoS) attacks on your gateway or mail server.

If you do not have a mail server in your network, there is no need to enable the IP Reputation engine. (If you do enable this engine anyway, it will have no negative effects.)

In addition, VStream Antispam allows you to define a Safe Sender List, which consists of senders who are exempt from the Block List and Content Based Antispam engines.

The following table provides a comparison of the VStream Antispam engines.

Comparison of VStream Antispam Engines

 

IP Reputation

Content Based Antispam and Block List

Supported Protocols

Protects mail servers only, and applies to the SMTP protocol only

Protects both mail servers and mail clients, and applies to both POP3 and SMTP protocols

Email Scanning Time

Scans the email before accepting the connection

Scans the email after accepting the connection

Detection Method

Examines the sender's IP address

Content Based Antispam examines the email's content, and Block List examines the email's Sender field.

SMTP Error Message

Does not return an SMTP error message to the email sender

Returns an SMTP error message to the email sender

Mail Rejection Method

Resets the TCP connection

Marks the email Subject line, marks the email header, rejects the email (SMTP only), or deletes the email (POP3 only)

Server Overload Protection

Prevents spammers from overloading gateway and mail server resources

Does not prevent spammers from overloading gateway and mail server resources

Important: In order to use VStream Antispam, your UTM-1 appliance must be subscribed to a Service Center.

In This Section

How VStream Antispam Works

Header Marking

Default Antispam Policy

Enabling/Disabling VStream Antispam

Viewing VStream Antispam Statistics

Configuring the Content Based Antispam Engine

Configuring the Block List Engine

Configuring the IP Reputation Engine

Configuring the VStream Antispam Policy

Configuring the Safe Sender List

Configuring VStream Antispam Advanced Settings

See Also

Using Antivirus and Antispam Filtering

Overview

Using VStream Antivirus

Using Centralized Email Filtering