Block analysis mode

Prev Next

Block analysis mode is one of the two analysis modes that can be used in MTA deployments, and is the default mode. In Block mode, the Email Security — Server appliance receives emails from an anti-spam device or MTA gateway. After email attachments and embedded URLs are analyzed, the appliance forwards all non-malicious emails to the next-hop for delivery to the intended recipients.

Malicious emails are moved to the quarantine folder, which only an Email Security — Server administrator can access. The eQuarantine and eAlerts tabs in the Email Security — Server Web UI provide comprehensive information about the malicious emails and analysis results. An administrator can remove or release the emails from the eQuarantine tab. Releasing emails from the quarantine effectively marks them as non-malicious, so they are delivered to the next-hop for delivery to the intended recipients.

In Block analysis mode, the appliance can notify the intended recipients that emails were not delivered because they were blocked. The appliance can also send "admin" notices about malicious emails to administrators, and can send "bcc" notices with copies of the malicious emails to forensic analysts.

Important

Trellix strongly recommends using Block mode. See Deployment considerations for details.

Task list for Block analysis mode

Perform the following steps to configure the Email Security — Server appliance to operate in Block analysis mode.

Note

This is the minimal configuration for Block analysis mode. For information about additional options, see the Email Security — Server User Guide.

  1. Ensure the following:

    • The appliance is deployed in MTA mode. (See the Hardware Administration Guide for details.)

    • The management interface and network access settings are configured correctly. (See Initial Configuration for details.)

    • The EMPS_ATTACHMENT_SCAN and EMPS_URL_SCAN licenses are installed and valid. (See License Management for details.)

  2. Enable Block analysis mode. (See Enabling the Analysis Mode for details.)

  3. Configure the SMTP interface. (See Configuring the SMTP Interface for details.)

  4. Specify the domain and next-hop addresses to which emails will be sent. (See Configuring Domain and Next-Hop Settings ) for details.)

  5. (Optional) Configure notices about malicious emails. (See Configuring Notices for details.)

  6. Use the reload command in the CLI configuration mode to reboot the appliance.