FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to:...

32
FortiGate Email Filtering

Transcript of FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to:...

Page 1: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

FortiGate Email Filtering

Page 2: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

Module Objectives

• By the end of this module participants will be able to:• Identify the email filtering methods used on the

FortiGate device

• Configure banned word, IP address and email address filters

• Define firewall policies using email filter profiles

• Identify the differences between the email filtering capabilities of the FortiGate and FortiMail units

Page 3: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

Email Filtering

Email filtering

SPAM?

Page 4: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

Email Filtering

Email filtering

SPAM?• FortiGate unit can detect and manage spam email

Page 5: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

Spam Actions

Tag Discard

Subject: Free Stuff

Subject: [SPAM] Free Stuff

Page 6: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

Spam Actions

Tag Discard

Subject: Free Stuff

Subject: [SPAM] Free Stuff• Tag to add a custom phrase/word to subject line or a MIME header and value to body of an email message•Discard to immediately drop connection if spam is detected

Page 7: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

Email Filtering Methods

• The FortiGate unit uses a number of techniques to help detect spam• Some use the FortiGuard Antispam service and require

a subscription• Others use DNS servers or filters created on the device

Click here to read more about the email filtering methods used on the FortiGate unit

Page 8: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

FortiGuard IP Address Check

Received: from mail.acme.com (10.10.10.1)by classroom.fortinet.com with SMTP; 30 Sept 2010 02:27:02 -0000

Page 9: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

FortiGuard IP Address Check

Received: from mail.acme.com (10.10.10.1)by classroom.fortinet.com with SMTP; 30 Sept 2010 02:27:02 -0000

• FortiGate unit queries the FortiGuard Antispam Service to determine if the source IP address of the sender is blacklisted• A match will cause the FortiGate unit to

treat the message as spam

Page 10: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

FortiGuard URL and Email Address Check

Visit our web site at www.acme.com tolearn more about this great offer orsend an email to [email protected].

Page 11: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

FortiGuard URL and Email Address Check

Visit our web site at www.acme.com tolearn more about this great offer orsend an email to [email protected].

• FortiGate unit queries the FortiGuard Antispam Service to determine if any URLs or email addresses in the message are associated with spam

Page 12: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

FortiGuard Email Checksum Check

Our online pharmacy offersgreat prices on all yourprescription medications.

hash

Page 13: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

FortiGuard Email Checksum Check

Our online pharmacy offersgreat prices on all yourprescription medications.

• The FortiGate unit sends a hash of the email message to the FortiGuard Antispam Service• FortiGuard Antispam Service compares the hash received to hashes of known spam messages

hash

Page 14: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

IP Address Black/White List (BWL)

Received: from mail.acme.com (10.10.10.1)by classroom.fortinet.com with SMTP; 30 Sept 2010 02:27:02 -0000

Mark as Clear

Mark as Spam

Mark as Reject

Page 15: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

IP Address Black/White List (BWL)

Received: from mail.acme.com (10.10.10.1)by classroom.fortinet.com with SMTP; 30 Sept 2010 02:27:02 -0000

• The FortiGate unit compares the IP address of the sender of an email message to the IP addresses specified in the email filter profile• An administrator can add to or edit the

IP addresses and configure the action to take

Mark as Clear

Mark as Spam

Mark as Reject

Page 16: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

Email Address Black/White List (BWL)

From: [email protected]

• The FortiGate unit compares the email address of the sender of an email message to the email addresses specified in the email filter profile• An administrator can add to or edit the

email addresses and configure the action to take

• Wild card and regular expressions can be used to define the email address

Mark as Clear

Mark as Spam

Click here to read more using regular expressions

Page 17: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

HELO DNS Lookup

DNSReceived: from mail.acme.com (10.10.10.1)by classroom.fortinet.com with SMTP; 30 Sept 2010 02:27:02 -0000

Page 18: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

HELO DNS Lookup

DNSReceived: from mail.acme.com (10.10.10.1)by classroom.fortinet.com with SMTP; 30 Sept 2010 02:27:02 -0000

• The FortiGate unit compares the source domain name of an email message to the registered IP address in DNS• If a domain is capable of sending mail,

it should be capable of receiving mail routed by DNS records

• SMTP only

Page 19: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

Return Email DNS Check

DNS

From: [email protected]

A or MX record

Page 20: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

Return Email DNS Check

DNS

From: [email protected]

A or MX record

• The FortiGate unit compares the address domain of an incoming email message to the registered IP address in DNS

Page 21: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

Banned Word Check

Let us fill all your prescriptiondrugs. Visit our online pharmacyfor great prices on prescription medications. We offer the widestselection of popular drugs.

Banned words

DrugsScore=10

PharmacyScore=5

PrescriptionScore=5

Threshold=18

10 +5 +5 =20

Click here to read more using regular expressions

Page 22: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

Banned Word Check

Let us fill all your prescriptiondrugs. Visit our online pharmacyfor great prices on prescription medications. We offer the widestselection of popular drugs.

Banned words

DrugsScore=10

PharmacyScore=5

PrescriptionScore=5

Threshold=18

10 +5 +5 =20

• The FortiGate unit can block email based on words or patterns in the message• A score is assigned to any banned words in the message• If the threshold is exceeded, the message is marked as spam•Wildcards and regular expressions can be used to define the banned words

Click here to read more using regular expressions

Page 23: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

MIME Headers Check

MIME-Version: 1.0Content-Type: multipart/mixed;X-Mailer: Microsoft Office Outlook, Build 11.0.5510X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165X-Distribution: Bulk

Header list

X-Distribution=Bulk

Mark as Clear

Mark as Spam

Page 24: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

MIME Headers Check

MIME-Version: 1.0Content-Type: multipart/mixed;X-Mailer: Microsoft Office Outlook, Build 11.0.5510X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165X-Distribution: Bulk

Header list

X-Distribution=Bulk

Mark as Clear

Mark as Spam• The FortiGate unit can check the MIME header information of incoming email messages• If a match is found on the header list

configured on the device, the corresponding action is taken

• Configured through CLI only• config spamfilter mheader

Page 25: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

DNSBL and ORDBL Check

Received: from mail.acme.com (10.10.10.1)by classroom.fortinet.com with SMTP; 30 Sept 2010 02:27:02 -0000

DNSBL

ORDBL

Page 26: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

DNSBL and ORDBL Check

Received: from mail.acme.com (10.10.10.1)by classroom.fortinet.com with SMTP; 30 Sept 2010 02:27:02 -0000

DNSBL

ORDBL• The FortiGate unit can compare the IP address or domain name of incoming email message against third-party DNSBL and ORDBL lists• Match IP addresses or domain names of

known spammers

• Configured though CLI only• config spamfilter dnsbl

• config spamfilter ordbl

Page 27: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

FortiGuard Email Filtering Options

Cache

IP address:10.10.10.1

URL: www.acme.com

Message checksum:x65Fsd34c

Page 28: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

FortiGuard Email Filtering Options

Cache

IP address:10.10.10.1

URL: www.acme.com

Message checksum:x65Fsd34c

• Caching improves performance by reducing FortiGate unit requests to FortiGuard servers• Small amount of FortiGate system memory dedicated to the cache• TTL settings controls the number of second query results are cached• Alternate port number of 8888 can be configured for access to FortiGuard servers

Page 29: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

Email Filter ProfileEmail filter profile: Class_Email_Filter

Firewall policy

Page 30: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

Email Filter ProfileEmail filter profile: Class_Email_Filter

Firewall policy

• Enable email filtering operations on a protocol-by-protocol basis in email filter profile• Profile in turn applied to firewall policy• Any traffic being examined by the

policy will have the email filter operations applied to it

Page 31: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

FortiMail Email Filtering

• Enhanced set of features for detecting and blocking spam• Some techniques not available

on FortiGate units

• Stand-alone email filtering system• Second layer of protection in

addition to FortiGate

• Legacy virus protection• Email quarantine

Page 32: FortiGate Email Filtering. Module Objectives By the end of this module participants will be able to: Identify the email filtering methods used on the.

Student Resources

Click here to view the list of resources used in this module