McAfee MAP-3300-SWG Product Guide - Page 75

Data command options, Denial of service protection, Table 48, Option definitions

Page 75 highlights

Overview of Email features Email Configuration Data command options Use this area to specify how the appliance responds during the DATA phase when handling SMTP email. Table 48 Option definitions Option Maximum message data size Definition Prevents large messages. Default value is No limit. Maximum length of a single line Prevents excessive line length. Default value is No limit. Maximum number of hops Specifies the maximum number of hops allowed, that is, the maximum number of Received lines allowed in the email header. Default value is 100. If these limits are exceeded Maximum line length before the message is re-encoded Specifies how the appliance responds. Default value is Close the connection. Default value is No limit. Denial of service protection Use this area to specify how the appliance prevents possible denial-of-service attacks on your mail server. Table 49 Option definitions Option Minimum data throughput Definition Prevents an average data throughput that is too low. An attacker might deliberately handle parts of the SMTP conversation slowly. Default value is No lower limit. Maximum number of trivial commands Prevents the appliance receiving too many trivial commands before a successful DATA command. An attacker might repeatedly send commands like HELO, EHLO, NOOP, VRFY, and EXPN. Default value is 100. Maximum number of AUTH attempts Prevents too many AUTH conversation attempts. (Transparent Bridge mode only). The SMTP AUTH command is a request to the email server for an authentication mechanism. Default value is No limit. Maximum command length Prevents excessive command length. This might be a buffer-overflow attack. According to RFC 2821, the maximum total length of a command line including the command word and the CR-LF is 512 characters. Default value is 999. Maximum duration of an SMTP conversation Limits the time between opening the connection and receiving the final dot (.) command. Default value is No limit. Allow null senders Accepts an empty From address. Default value is Yes. Reject recipient if the domain is Default value is No. not routable McAfee Email and Web Security Appliances 5.6.0 Product Guide 75

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336

Data command options
Use this area to specify how the appliance responds during the DATA phase when handling SMTP email.
Table 48
Option definitions
Option
Definition
Maximum message data size
Prevents large messages.
Default value is No limit.
Maximum length of a single line
Prevents excessive line length.
Default value is No limit.
Maximum number of hops
Specifies the maximum number of hops allowed, that is, the
maximum number of Received lines allowed in the email header.
Default value is 100.
If these limits are exceeded
Specifies how the appliance responds. Default value is
Close the
connection
.
Maximum line length before the message is
re-encoded
Default value is No limit.
Denial of service protection
Use this area to specify how the appliance prevents possible denial-of-service attacks on your mail server.
Table 49
Option definitions
Option
Definition
Minimum data throughput
Prevents an average data throughput that is too low. An attacker might
deliberately handle parts of the SMTP conversation slowly.
Default value is No lower limit.
Maximum number of trivial
commands
Prevents the appliance receiving too many trivial commands before a
successful DATA command. An attacker might repeatedly send commands
like HELO, EHLO, NOOP, VRFY, and EXPN.
Default value is 100.
Maximum number of AUTH
attempts
Prevents too many AUTH conversation attempts. (Transparent Bridge
mode only). The SMTP AUTH command is a request to the email server for
an authentication mechanism.
Default value is No limit.
Maximum command length
Prevents excessive command length. This might be a buffer-overflow
attack. According to RFC 2821, the maximum total length of a command
line including the command word and the CR-LF is 512 characters.
Default value is 999.
Maximum duration of an SMTP
conversation
Limits the time between opening the connection and receiving the final
dot (.) command.
Default value is No limit.
Allow null senders
Accepts an empty
From
address.
Default value is Yes.
Reject recipient if the domain is
not routable
Default value is No.
Overview of Email features
Email Configuration
McAfee Email and Web Security Appliances 5.6.0 Product Guide
75