<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint MTA R80.40 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/121957#M22608</link>
    <description>&lt;P&gt;Is there not a simple way to say:&lt;/P&gt;&lt;P&gt;SRC: server A DST: server B Action: Accept&lt;/P&gt;&lt;P&gt;as an exception that will bypass the Anti-SPAM policy?&lt;/P&gt;&lt;P&gt;I can send PDF attachments out of the email server all day I just can't relay an&lt;/P&gt;&lt;P&gt;email that contains a PDF to the mail server. Bizarre.&lt;/P&gt;</description>
    <pubDate>Wed, 23 Jun 2021 18:01:28 GMT</pubDate>
    <dc:creator>Tony_Graham</dc:creator>
    <dc:date>2021-06-23T18:01:28Z</dc:date>
    <item>
      <title>Checkpoint MTA R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/121950#M22603</link>
      <description>&lt;P&gt;Not sure if this is posting to the correct place but here is my issue.&lt;/P&gt;&lt;P&gt;I am working on deploying the Checkpoint MTA for anti-spam functionality.&lt;/P&gt;&lt;P&gt;I got it set up without any problems and mail is flowing. However, I have a specific&lt;/P&gt;&lt;P&gt;system that sends PDF reports. That system interacts with our main mail server which&lt;/P&gt;&lt;P&gt;sends the reports out on its behalf. Once those emails reach the firewall, they are getting&lt;/P&gt;&lt;P&gt;inspected and dropped as SPAM. I have set the MTA to inspect only on External interfaces&lt;/P&gt;&lt;P&gt;and I have tried all manner of exceptions but they are still getting flagged. Cannot seem&lt;/P&gt;&lt;P&gt;to find the magic clicky box to sort it out. Ideally I don't need it looking at emails going out&lt;/P&gt;&lt;P&gt;at all. Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;**I should also mention this is R80.40&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 15:32:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/121950#M22603</guid>
      <dc:creator>Tony_Graham</dc:creator>
      <dc:date>2021-06-23T15:32:24Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint MTA R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/121955#M22606</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/24239"&gt;@Tony_Graham&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;a screenshot from the log entry would be helpful. There should be seen which feature (content, IP reputation etc.) block or flag the message.&lt;/P&gt;
&lt;P&gt;Are you sure MTA is dropping these, AntiSpam feature will be configured outside of the ThreatPrevention profile via old SmartDashboard . There you can define exception for AntiSpam.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 17:13:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/121955#M22606</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2021-06-23T17:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint MTA R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/121956#M22607</link>
      <description>&lt;P&gt;It says in the log,&lt;/P&gt;&lt;P&gt;Action:Reject&lt;/P&gt;&lt;P&gt;Blade: Anti-SPAM and Email Security&lt;/P&gt;&lt;P&gt;Drilling down into event---&lt;/P&gt;&lt;P&gt;Reason:Suspected SPAM Rejected&lt;/P&gt;&lt;P&gt;File direction: Internal to Internal&lt;/P&gt;&lt;P&gt;There is an Accept log entry before the Reject for the each connection. The Accept log for the connection&lt;/P&gt;&lt;P&gt;reads:&lt;/P&gt;&lt;P&gt;Description: Non Spam Accepted&lt;/P&gt;&lt;P&gt;Email Control: IP Reputation&lt;/P&gt;&lt;P&gt;There is also reference to Policy Rule 6, which is in reference to my allow SMTP connections from the originating server to the destination.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do not&amp;nbsp; understand what this means:&lt;/P&gt;&lt;P&gt;" AntiSpam feature will be configured outside of the ThreatPrevention profile via old SmartDashboard ."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 17:40:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/121956#M22607</guid>
      <dc:creator>Tony_Graham</dc:creator>
      <dc:date>2021-06-23T17:40:03Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint MTA R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/121957#M22608</link>
      <description>&lt;P&gt;Is there not a simple way to say:&lt;/P&gt;&lt;P&gt;SRC: server A DST: server B Action: Accept&lt;/P&gt;&lt;P&gt;as an exception that will bypass the Anti-SPAM policy?&lt;/P&gt;&lt;P&gt;I can send PDF attachments out of the email server all day I just can't relay an&lt;/P&gt;&lt;P&gt;email that contains a PDF to the mail server. Bizarre.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 18:01:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/121957#M22608</guid>
      <dc:creator>Tony_Graham</dc:creator>
      <dc:date>2021-06-23T18:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint MTA R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/121962#M22610</link>
      <description>&lt;P&gt;First of all, I think you enabled the MTA and the blade „&lt;SPAN&gt;Anti-SPAM and Email Security“.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you don‘t understand my writing about the old SmartDashboard you did no configuration of the AntiSpam blade. These blade is one of the odd behaviour with some features they are still not available in SmartConsole.&amp;nbsp;&lt;BR /&gt;Maybe in version R100 or anything else all features will be configurable in only one GUI !&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Follow these……&lt;/P&gt;
&lt;P class="procedureheading"&gt;To configure a content Anti-Spam policy:&lt;/P&gt;
&lt;OL class="listnumber"&gt;
&lt;LI class="listnumber"&gt;In SmartConsole, select &lt;STRONG class="menuoptions"&gt;Manage &amp;amp; Settings&lt;/STRONG&gt; &amp;gt;&lt;STRONG class="menuoptions"&gt; Blades &lt;/STRONG&gt;&amp;gt; &lt;STRONG class="menuoptions"&gt;Anti-Spam&lt;/STRONG&gt;&lt;STRONG class="menuoptions"&gt; &amp;amp; Mail &lt;/STRONG&gt;&amp;gt; and click &lt;STRONG class="menuoptions"&gt;Configure in SmartDashboard&lt;/STRONG&gt;.
&lt;P class="listcontinue"&gt;SmartDashboard opens and shows the &lt;STRONG class="menuoptions"&gt;Anti-Spam&lt;/STRONG&gt;&lt;STRONG class="menuoptions"&gt; &amp;amp; Mail&lt;/STRONG&gt; tab.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="listnumber"&gt;On the &lt;STRONG class="menuoptions"&gt;Overview&lt;/STRONG&gt; page, under &lt;STRONG class="menuoptions"&gt;Content based Anti-Spam&lt;/STRONG&gt;, click &lt;STRONG class="menuoptions"&gt;Settings&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI class="listnumber"&gt;Use the slider to select an Anti-Spam policy protection level.&lt;/LI&gt;
&lt;LI class="listnumber"&gt;Select flagging options.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;There are too options to define exceptions for IPs or mail addresses. Detailed configuration options are find in the documentation:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_ThreatPrevention_AdminGuide/Topics-TPG/Using_Anti_Spam_and_Mail.htm?Highlight=Spam#Using_Anti-Spam_and_Mail" target="_blank" rel="noopener"&gt;Using Anti-Spam and Mail&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Your first log entry shows „&lt;SPAN&gt;Email Control: IP Reputation“. This means that the AntiSpam-blade does not drop this connection regarding the „IP reputation“ feature (blacklist check…) I think the same field in the second log (the drop log) shows something like „Email Control: Content AntiSpam“. Which means something of the content in the message is detected as spam.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Wolfgang&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 19:09:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/121962#M22610</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2021-06-23T19:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint MTA R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/121964#M22611</link>
      <description>&lt;P&gt;Thanks Wolfgang. I will take some time and digest what you have said.&lt;/P&gt;&lt;P&gt;Part of the problem also is I have been managing CP since version 2 and&lt;/P&gt;&lt;P&gt;I have a lot of 'cruft' information stored in my brain that is often irrelevant because&lt;/P&gt;&lt;P&gt;it has been superseded by newer processes. Still trying to wrap my head around this.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 19:39:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/121964#M22611</guid>
      <dc:creator>Tony_Graham</dc:creator>
      <dc:date>2021-06-23T19:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint MTA R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/121966#M22612</link>
      <description>&lt;P&gt;Okay so do I not need the MTA and the blade? I am a bit confused on that.&lt;/P&gt;&lt;P&gt;I do have the blade enabled and working and I can watch the traffic in the logs.&lt;/P&gt;&lt;P&gt;I have the MTA operating on another IP for testing purposes but as I said, not sure&lt;/P&gt;&lt;P&gt;if this is needed or desired to be used.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 23:35:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/121966#M22612</guid>
      <dc:creator>Tony_Graham</dc:creator>
      <dc:date>2021-06-23T23:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint MTA R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/121983#M22613</link>
      <description>&lt;P&gt;The clear answer of your question (Do I need the MTA?) "it depends...." &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If you want to have one of these features from the ThreatPreventionProfile you need to enable MTA.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-06-24 081541.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12297iD4963763B734DF9B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2021-06-24 081541.png" alt="Screenshot 2021-06-24 081541.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Another point will be that a lot of the SMTP traffic is encrypted. Without MTA you can't analyze these messages.&lt;/P&gt;
&lt;P&gt;Without MTA you can still use the "AntiSpam-EmailSecurity"-blade. IP reputation will work, and content scan for SPAM&lt;BR /&gt;will work for unencrypted message flow.&lt;/P&gt;
&lt;P&gt;I prefer to use both but you have to be aware that now another MTA is involved in the message flow which has to be monitored.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 06:17:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/121983#M22613</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2021-06-24T06:17:43Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint MTA R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/122106#M22634</link>
      <description>&lt;P&gt;What about the items above where you have circled? It seems like they may be covered elsewhere at this point.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 19:40:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/122106#M22634</guid>
      <dc:creator>Tony_Graham</dc:creator>
      <dc:date>2021-06-24T19:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint MTA R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/122151#M22639</link>
      <description>&lt;P&gt;These are options in the ThreatPreventionProfile named "optimized". If you enable MTA,&amp;nbsp;an automatic rulle is created as first rule in the ThreatPrvention policy with MTA-gateway as "protected scope".&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Screenshot 2021.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12335i23A5B56FEA146E5D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021.png" alt="Screenshot 2021.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 06:50:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/122151#M22639</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2021-06-25T06:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint MTA R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/122217#M22648</link>
      <description>&lt;P&gt;So I am wondering how much overlap there is between the two products? MTA which enables TP, and Enabling the server Blade Anti-SPAM and email security, not to mention ThreatCloud monitoring. It's just not clear where one ends and one begins. Is there a chart?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 18:20:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/122217#M22648</guid>
      <dc:creator>Tony_Graham</dc:creator>
      <dc:date>2021-06-25T18:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint MTA R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/122226#M22651</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/24239"&gt;@Tony_Graham&lt;/a&gt;&amp;nbsp; I agree with you. The mail security on a Check Point gateway is a little bit confusing. There is no overlapping feature between AntiSpam blade and ThreatPrevention Mail Security. But it‘s really confusing you have to configure mail security in different GUI tools with separate locations. All the features are described in the Threat Prevention documentation I mentioned earlier.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 19:57:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-MTA-R80-40/m-p/122226#M22651</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2021-06-25T19:57:16Z</dc:date>
    </item>
  </channel>
</rss>

