McAfee MAP-3300-SWG Product Guide - Page 92

Suggested simple configuration, Create a permitted subdomain based on a larger denied domain, Table 70

Page 92 highlights

Overview of Email features Email Configuration Table 70 Option definitions (continued) Option Definition Denied routing characters Accepts any of the following characters: *%* - Right-binding routing character (%-exploit). *!* - Local or mail gateway routing. *|* - Pipe is used by some mail servers to execute commands. *[*]* - Parentheses that encloses a dotted-decimal domain address such as 192.168.254.200. *:* - Colon for multiple hops. For example, to block the relaying of addresses of the type "user@host"@relay.com, add *@* to the list of denied characters. Use the default (Denied When selected, prevents the use of the following routing characters: *!* *%* *| routing characters) * Enable routing character When selected, examines routing characters on outgoing mail. checking for sender Protocol preset Lists any connection-based policies to which the routing characters setting applies. Click to open the Protocol Presets screen to assign additional policies, or create new policies or network groups to which the routing characters setting applies. Suggested simple configuration To allow relaying of incoming messages to your domain, add a wildcard domain. To allow the relaying of outgoing messages from your domain, add the IP address or network address of the Message Transfer Agent (MTA): 1 Go to Email | Email Configuration | Receiving Email | Anti-Relay Settings. 2 Click Add Domain. 3 Type the domain name using a wildcard, such as *example.dom. 4 In Category, select Local domain, and click OK. 5 Click Add Domain, and type the network address or the IP address from which you expect to receive messages (such as 192.168.0.2/32 or 192.168.0.0/24). 6 In Category, select Local domain, and click OK. Create a permitted subdomain based on a larger denied domain To create a small permitted subdomain within a larger denied domain, create the main domain as a denied domain, and add the sub domain as a permitted domain. 1 Go to Email | Email Configuration | Receiving Email | Anti-Relay Settings. 2 Click Add Domain. 3 Type the domain name that you want to deny using a wildcard, such as *example.dom to reject all messages sent to that domain. 4 In Category, select Denied domain, and click OK. 92 McAfee Email and Web Security Appliances 5.6.0 Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336

Table 70
Option definitions
(continued)
Option
Definition
Denied routing characters
Accepts any of the following characters:
*%* - Right-binding routing character (%-exploit).
*!* — Local or mail gateway routing.
*|* — Pipe is used by some mail servers to execute commands.
*[*]* — Parentheses that encloses a dotted-decimal domain address such as
192.168.254.200.
*:* — Colon for multiple hops.
For example, to block the relaying of addresses of the type
“user@host”@relay.com, add *@* to the list of denied characters.
Use the default (Denied
routing characters)
When selected, prevents the use of the following routing characters: *!* *%* *|
*
Enable routing character
checking for sender
When selected, examines routing characters on outgoing mail.
Protocol preset
Lists any connection-based policies to which the routing characters setting
applies.
Click to open the
Protocol Presets
screen to assign additional policies, or create
new policies or network groups to which the routing characters setting applies.
Suggested simple configuration
To allow relaying of incoming messages to your domain, add a wildcard domain. To allow the relaying
of outgoing messages from your domain, add the IP address or network address of the Message
Transfer Agent (MTA):
1
Go to
Email
|
Email Configuration
|
Receiving Email
|
Anti-Relay Settings
.
2
Click
Add Domain
.
3
Type the domain name using a wildcard, such as
*example.dom
.
4
In Category, select
Local domain
, and click
OK
.
5
Click
Add Domain
, and type the network address or the IP address from which you expect to receive
messages (such as 192.168.0.2/32 or 192.168.0.0/24).
6
In Category, select
Local domain
, and click
OK.
Create a permitted subdomain based on a larger denied domain
To create a small permitted subdomain within a larger denied domain, create the main domain as a
denied
domain, and add the sub domain as a
permitted
domain.
1
Go to
Email
|
Email Configuration
|
Receiving Email
|
Anti-Relay Settings
.
2
Click
Add Domain
.
3
Type the domain name that you want to deny using a wildcard, such as
*example.dom
to reject all
messages sent to that domain.
4
In Category, select
Denied domain
, and click
OK
.
Overview of Email features
Email Configuration
92
McAfee Email and Web Security Appliances 5.6.0 Product Guide