Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
gemechisd
Contributor

AntiSpam and Email Security

We have check point gateway with 7000 series. And last month we have updated our license. So, we want to use Anti Spam & Email Security feature. How can we enable that? How can we configure any rules for that associated blade? If there are things we need to know before enabling that feature?

0 Kudos
19 Replies
Lesley
Mentor Mentor
Mentor

Start with the relevant documentation: 

https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_ThreatPrevention_AdminGuide/...

 

Here a FAQ regarding MTA:

https://support.checkpoint.com/results/sk/sk108553

https://support.checkpoint.com/results/sk/sk109699

Why you might need MTA:

https://support.checkpoint.com/results/sk/sk98973

Not sure you run VSX but this is not supported:

https://support.checkpoint.com/results/sk/sk79700

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
gemechis
Explorer

@Lesley thanks for the detail explanation.

Is enabling MTA a must to use Anti spam and email security? And what are both the advantages and disadvantages of MTA enabling on a maestro? 

0 Kudos
PhoneBoy
Admin
Admin

If email is transported with TLS, an MTA is required as we won't be able to see the mail content otherwise.

0 Kudos
Wolfgang
Authority
Authority

@gemechis MTA is not required for AntiSpam-Blade. Without MTA you have features like BlackList block, IP reputation and content spam check for messages they are not sent encrypted (mentioned by @PhoneBoy )

ThreatExtraction (SandBoxing, remove malicious content from file-attachments or convert to pdf) requires MTA.

As a hint....All features they must be configured in the old SmartDasboard can be used without MTA. All other configuration in the mail tab of ThreatPrevention-Profile needs MTA enabled.

0 Kudos
(1)
gemechis
Explorer

@Wolfgang Thanks for the reply.

Today, I have tried to configure "Configuring a Content Anti-Spam Policy", "Configuring an IP Reputation Policy", "Configuring a Block List". From this 3, IP retutation is working. But we tried to block using domains but emails are arriving at our mailbox.

What could be the issue. I have not enabled MTA, 

Any help on this 

0 Kudos
gemechis
Explorer

@Lesley @PhoneBoy @Wolfgang 

I have checked all MTA articles and found there are three (3) deployment methods for it.
1. Check Point MTA as the organization MX record
2. Check Point MTA as an internal MTA
3. Check Point MTA in BCC Mode

My question is that if we configure using option 3 which is "Check Point MTA in BCC Mode" How does the mail extraction and emulation going to be done? 

0 Kudos
PhoneBoy
Admin
Admin

In BCC mode, a copy of the email is sent to emulation, but it is not prevented from reaching the end users inbox.
For full prevention, you need to deploy it with one of the other methods.

0 Kudos
(1)
gemechis
Explorer

Hi @PhoneBoy 

Thanks for the reply.

Today, I have tried to configure "Configuring a Content Anti-Spam Policy", "Configuring an IP Reputation Policy", "Configuring a Block List". From this 3, IP retutation is working. But we tried to block using domains but emails are arriving at our mailbox.

What could be the issue. I have not enabled MTA, 

0 Kudos
PhoneBoy
Admin
Admin

If SMTP is sent via TLS, then you will not be able to block by domain as there is no way to see what domains are involved in the email.
In this case, you will need to use MTA mode.

0 Kudos
(1)
gemechis
Explorer

@PhoneBoy okay.

So,
      1. Which one's can I configure without enabling MTA?
      2. If enabling MTA is a must to, which mode do you recommend considering resource utilization.


0 Kudos
Wolfgang
Authority
Authority

@gemechisd There are not much configuration options. You have to enable the blade and most of the things are configured via the old SmartDashboard. There you can enable AntiSpam- and IPreputation-level  and configure exceptions. If you enable the MTA on the gateway you can use your TP profile to check messages for viruses and emulate files in TP environment. 
AntiSpam and IP-reputation both have really good results but configuration options are very limited. No quarantine, limited exceptions, no address checking in the internal mail environment……

0 Kudos
(1)
gemechis
Explorer

@Wolfgang Thanks for the explanation. But If don't want to enable MTA is AntiSpam and IP-reputation the only option working without MTA? 

Who is responsible for analysing attachments?

0 Kudos
gemechis
Explorer

We have a check point deployment in our environment and we need to enable the "Anti Spam and Email Security" Blade. And we need to configure 

  • Content Anti-Spam Policy
  • IP Reputation Policy
  • Block List
  • Anti-Spam SMTP
  • Anti-Spam POP3

After enabling the blade, I have configured the IP Reputation and Block list. And the IP Reputation worked but the block list is not. what could be enabled to see the block list working in our environment. 

0 Kudos
Chris_Atkinson
Employee Employee
Employee

What have you configured in the block list ip/domain/email?

Is anti-spam seeing SMTP TLS traffic (sk98973)?

CCSM R77/R80/ELITE
0 Kudos
gemechis
Explorer

Yes. It's encrypted. 

0 Kudos
the_rock
Legend
Legend

Would you mind send us some screenshots how this is configured? Just blur out the sensitive data.

Andy

0 Kudos
gemechis
Explorer

@the_rock 

Below you can find the screenshots.

0 Kudos
the_rock
Legend
Legend

Looks right. I would confirm with TAC, but what Phoneboy said seems most logical.

Andy

0 Kudos
gemechis
Explorer

@the_rock 

Ok. one thing i need to clarify. What are the possible configurations I can do with out enabling MTA?

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events