Analysis modes

Prev Next

The manner in which the Email Security - Server appliance receives emails and the actions it takes after it analyzes them depend on its deployment mode and the associated analysis modes.

  • Block analysis mode—The Email Security - Server appliance receives emails from an antispam device or MTA gateway. After email attachments and embedded URLs are analyzed, the appliance forwards all non-malicious emails to the next hop for delivery to the intended recipients. This is the default mode.

    For details about how to operate in Block analysis mode, refer to the "Block Analysis Mode" section of the Email Security — Server System Administration Guide.

  • Drop analysis mode—The Email Security - Server appliance extracts a copy of all email traffic from an antispam device or MTA gateway. After email attachments and embedded URLs are analyzed, non-malicious emails are discarded.

    For details about how to operate in Drop analysis mode, refer to the "Drop Analysis Mode" section of the Email Security — Server System Administration Guide.

  • Monitor analysis mode—The Email Security - Server appliance receives emails from an antispam device or MTA gateway. The appliance forwards all emails (including malicious emails) to the next hop for delivery to the intended recipients.

    For details about how to operate in Monitor analysis mode, refer to the "Monitor Analysis Mode" section of the Email Security — Server System Administration Guide.

  • Tap/Span analysis mode—The Email Security - Server appliance listens passively for SMTP traffic from a network switch with port mirroring capabilities. The switch forwards all SMTP traffic to the Email Security - Server appliance through port 25, and the appliance extracts emails from the raw traffic. After the email attachments and embedded URLs are analyzed, non-malicious emails are discarded. You can also allow the Email Security - Server appliance to send another email to notify the recipient if a malicious email was detected.

    For details about how to operate in Tap/Span analysis mode, refer to the "Tap/Span Analysis Mode" section of the Email Security — Server System Administration Guide.

Caution

Trellix strongly recommends the Block analysis mode, which is an inline deployment option. The Block mode is the most effective option, because the Email Security - Server appliance scans every email and prevents malicious emails from being delivered to the intended recipients. This is the default analysis mode. If you are considering another analysis mode, make sure you understand the implications of changing the mode. For details, see the “Analysis Mode Configuration” section of the Email Security — Server System Administration Guide.

Important

After you change the analysis mode, use the reload command in the CLI configuration mode to reboot the appliance. Otherwise, email will not be delivered to the downstream MTA after you change to Block or Monitor mode, and the SMTP or pether3 interface will not be reset properly.

Prerequisites

  • Administrator or Operator access to the Email Security - Server appliance .