- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Harmony Mobile 4:
New Version, New Capabilities
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hello guys !
I need your help kinda urgently ...
Im going tomorrow to a customer's site and I need to block outgoing mails from the exchange server to the internet with content awareness.
I tried creating a rule saying that the exchange server is the source and the internet is the destination(drop rule for a certain data type) and the firewall just didn't catch the traffic that it was supposed to catch(we tried sending test mails from the internal exchange to a gmail email).
To my understanding, I need to enable mail transfer agent so that the firewall could open up the mail completely and analyze it.
Can anyone help with how to configure the above scenario ?
Nadav,
first of all, I would prefer to ask such question a little bit earlier.
MTA on gateway is only for incoming mail traffic, no configuration for outgoing to the internet possible.
Why you don‘t block service SMTP from the mailserver to the whole Internet or only some destination hosts?
Wolfgang
Nadav,
you can do this with "content awareness" and a rule catching SMTP-traffic and as inline-layer block some file-types with content awareness.
But the problem is,if your connection is SMTPS (encrypted SMTP) you can't check anything inside the SMTP-connection.
For these you need a MTA to intercept the connection. This can't be done with the normal MTA for outgoing mails.
Wolfgang
Nadav,
you have to enable "content awareness" on the gateway and on your policy layer.
Create a rule matching the traffic and in content awareness field add your file types to block.
That's all you need.
Please be sure that the SMTP traffic is really unencrypted. If you see in the logs something like "bypass" as action or "Encrypted session" in information field, your SMTP session is encrypted.
Wolfgang
If you see bypass, the connection is encrypted.
I don't know a way to inspect an encrypted outgoing SMTP session on a CheckPoint gateway. If the session is encrypted they can't be inspected by any vendor. You need to send your messages without encryption going over your gateway or you have to choose another solution. Why don't need the PineApp solutions ? I'm not familiare with that but it sounds like a system to block content of messages.
Wolfgang
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY