<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint Anti Spam engine customization in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36471#M97184</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank your for your feedback. Nevertheless, what I can see at sk109699 is that "&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;MTA can function as an Anti-Spam starting in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk97617" style="color: #905690; background-color: #ffffff; text-decoration: none; font-size: 14px;" target="_blank"&gt;R77.10&lt;/A&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&amp;nbsp;" so my guess is that it has some of those features included also. The false positives we are experiencing are mainly from gmail and outlook.com servers which are being massively listed at CASA CBL and SORBS. I might be wrong, but that leads me to consider the option that RBL checking is in place. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Hence the question, as the messages themselves are clean and free of malware and/or spam.&amp;nbsp;The anti spam engine logs only show a cath all&amp;nbsp; "Spam Rejected" message and we have no way to find out exactly why - no details on the reason why they are tagged are presented.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 19 Mar 2018 15:22:52 GMT</pubDate>
    <dc:creator>Rui_Meleiro</dc:creator>
    <dc:date>2018-03-19T15:22:52Z</dc:date>
    <item>
      <title>Checkpoint Anti Spam engine customization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36469#M97182</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm placing this question here as the documentation is elusive on this and eventually someone might have encountered this questions and eventually found answers to them. These are all related to the Checkpoint Gateway Postfix MTA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. What RBLs - if any - are used on the engine?&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;Postfix normally is installed with SpamAssassin and ClamAV. Is this the case on the embedded Postfix MTA?&lt;/P&gt;&lt;P&gt;3. Is it possible to deploy the policyd-weight daemon on this Postfix build?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2018 13:13:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36469#M97182</guid>
      <dc:creator>Rui_Meleiro</dc:creator>
      <dc:date>2018-03-19T13:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Anti Spam engine customization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36470#M97183</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. With RBL you mean &lt;STRONG&gt;Real-time Blackhole List&lt;/STRONG&gt;s ? The CP MTA is only the GW agent that completes and closes the connection with the source e-mail server and then sends the file for emulation. After the emulation is complete, the MTA sends the e-mail to the mail server on the internal network. If the Anti-SPAM Blade is enabled, this should be much better than RBLs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. and 3. have to be answered with "not that i would know", but you can find in-depth details for CP MTA in &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk109699&amp;amp;partition=Advanced&amp;amp;product=Mail"&gt;&lt;EM&gt;sk109699 Mail Transfer Agent (MTA).&lt;/EM&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2018 13:27:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36470#M97183</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-03-19T13:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Anti Spam engine customization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36471#M97184</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank your for your feedback. Nevertheless, what I can see at sk109699 is that "&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;MTA can function as an Anti-Spam starting in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk97617" style="color: #905690; background-color: #ffffff; text-decoration: none; font-size: 14px;" target="_blank"&gt;R77.10&lt;/A&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&amp;nbsp;" so my guess is that it has some of those features included also. The false positives we are experiencing are mainly from gmail and outlook.com servers which are being massively listed at CASA CBL and SORBS. I might be wrong, but that leads me to consider the option that RBL checking is in place. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Hence the question, as the messages themselves are clean and free of malware and/or spam.&amp;nbsp;The anti spam engine logs only show a cath all&amp;nbsp; "Spam Rejected" message and we have no way to find out exactly why - no details on the reason why they are tagged are presented.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2018 15:22:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36471#M97184</guid>
      <dc:creator>Rui_Meleiro</dc:creator>
      <dc:date>2018-03-19T15:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Anti Spam engine customization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36472#M97185</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;EM&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108553&amp;amp;partition=General&amp;amp;product=Mail"&gt;sk108553 Mail Transfer Agent (MTA) - FAQ&lt;/A&gt; &lt;/EM&gt; lists that there are 2 ways to scan SMTP traffic:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Streaming (through the FireWall kernel) - works for all blades&lt;/LI&gt;&lt;LI&gt;MTA (through user space and using postfix) - works for Threat Emulation, Threat Extraction, Anti-Spam &amp;amp; E-mail Security&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;So all depends on which blades are licensed and enabled. If AntiSPAM is not enabled, you should not experience any false positives.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2018 15:40:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36472#M97185</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-03-19T15:40:06Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Anti Spam engine customization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36473#M97186</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another ressource for MTA issues is &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120260&amp;amp;partition=Advanced&amp;amp;product=Mail"&gt;&lt;EM&gt;sk120260 MTA Debugging and Performance Troubleshooting Toolkit&lt;/EM&gt;&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2018 15:50:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36473#M97186</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-03-19T15:50:18Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Anti Spam engine customization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36474#M97187</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All three blades (Threat Emulation, Threat Extraction and Anti-Spam ) are enabled, along with&amp;nbsp;a few others. I've activated MTA as there was the possibility of timeouts on the mail servers without it as the Threat Extraction and Threat Emulation blades would eventually cause that,&lt;/P&gt;&lt;P&gt;Allow me to dive in a little bit on your&amp;nbsp;sentence regarding Anti Spam, as I would like to understand it.&lt;/P&gt;&lt;P&gt;Disabling Anti Spam would certainly eliminate false positives, along with false negatives.&lt;/P&gt;&lt;P&gt;Or, are you saying that with the other blades enabled, the Anti Spam engine would not be required at all?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2018 15:51:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36474#M97187</guid>
      <dc:creator>Rui_Meleiro</dc:creator>
      <dc:date>2018-03-19T15:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Anti Spam engine customization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36475#M97188</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What i really wanted to say is that CP Anti-SPAM uses the CP Cloud for IP lookup and a message content verdict - no use of standard RBLs is known here...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2018 15:57:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36475#M97188</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-03-20T15:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Anti Spam engine customization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36476#M97189</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, my thoughts exactly.&amp;nbsp;Cloud IP lookup or similar&amp;nbsp;looks the same as Realtime Black List check, verify-this-ip or other variations on the same concept. My problem is that I'm fighting a whole lot of false positives on Checkpoint. These false positives cause havoc in our business relationships with our partners. And I'm given no cue on the why that's happening.Short of disabling the security features that made me choose Checkpoint in the first place, I have to search high and low for reasons and explanations. And I'm not getting them anywhere.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2018 17:49:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36476#M97189</guid>
      <dc:creator>Rui_Meleiro</dc:creator>
      <dc:date>2018-03-20T17:49:54Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Anti Spam engine customization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36477#M97190</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would suggest to do instead what i do at home - use Thunderbirds Bayes-Filter for Junk processing &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 08:00:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36477#M97190</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-03-21T08:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Anti Spam engine customization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36478#M97191</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm&amp;nbsp;not sure we're on the same page anymore. I'm not looking for alternatives to Checkpoint. We made a huge investment on Checkpoint gateways months ago and require them to work as&amp;nbsp;advertised. I'm well aware of&amp;nbsp;my options and the market alternatives out there. I just don't want to&amp;nbsp;throw money away.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 10:04:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36478#M97191</guid>
      <dc:creator>Rui_Meleiro</dc:creator>
      <dc:date>2018-03-21T10:04:04Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Anti Spam engine customization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36479#M97192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In short, no. Apparently Checkpoint uses their own spam fu to&amp;nbsp;identify spam messages using what they call spam patterns. No disclosure on what they are, the methods involved and therefore no hint on how to prevent those. This costed us 12 days of communications havoc with some of our business partners who had their messages tagged as spam due to...something. Truth be told, false positives are scarce with Checkpoint gateways. In this case, the spam pattern was in our own mail corporate signatures. We are not&amp;nbsp;detecting spam&amp;nbsp;outbound and when the messages&amp;nbsp;began being replied, well...you get the idea.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2018 10:31:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36479#M97192</guid>
      <dc:creator>Rui_Meleiro</dc:creator>
      <dc:date>2018-03-23T10:31:24Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Anti Spam engine customization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36480#M97193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Quite nice to mark ones own dissatisfied rant as the correct answer - but question is: The correct answer to which question &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2018 10:44:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36480#M97193</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-03-23T10:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Anti Spam engine customization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36481#M97194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not sure why you think any of my messages is a rant. And please excuse me if I'm breaking any unwritten netiquette.&lt;/P&gt;&lt;P&gt;I placed&amp;nbsp; three questions four days ago. The answer for all those three questions is no (explanation follows).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2018 10:55:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36481#M97194</guid>
      <dc:creator>Rui_Meleiro</dc:creator>
      <dc:date>2018-03-23T10:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Anti Spam engine customization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36482#M97195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Because you are just complaining - things (also sh..) happen, and with very complicated soft- and hardware, possible bugs or missconfiguration may even kill a company ! But that is something we all should know. Your questions had CP internals as a target, and the chance for answers seems zero to me - as this is a public site, and every competitor could read it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, any complaining about a product that for you did not bring enough value for the money spent or even did not work as expected at all is quite understandable - but surely not a correct answer to your questions, as they would not be real questions if you know the answers, but only traps...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2018 11:22:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36482#M97195</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-03-23T11:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Anti Spam engine customization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36483#M97196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These are not complaints at all. I have a responsibility to my company and to all its stakeholders. This post was part of a search&amp;nbsp;for a solution to a problem that was hurting my company. It was related to a trial-and-error process as no documentation existed on the issue at hand...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But this is getting completely off-topic. Thank you for your insights.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2018 12:10:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36483#M97196</guid>
      <dc:creator>Rui_Meleiro</dc:creator>
      <dc:date>2018-03-23T12:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Anti Spam engine customization</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36484#M97197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are right to complain, as I feel like we were sold damaged goods! We are getting more spam then ever. Had tickets open with CP for a few weeks now. Wow, Cisco ESA that was 12 years old did a much better job! Terrible design. Geo policy doesn't even work on MTA. (3200 series)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2019 17:49:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Anti-Spam-engine-customization/m-p/36484#M97197</guid>
      <dc:creator>Tim_Cole</dc:creator>
      <dc:date>2019-01-10T17:49:57Z</dc:date>
    </item>
  </channel>
</rss>

