Deployment best practices

Prev Next

Follow these guidelines for an optimal deployment of your Email Security — Server appliance.

  • Use actual traffic statistics in your network to estimate the deployment size.

    • The Email Hourly Stat report provides an hourly breakdown of the email traffic in CVS format. The first section of the report provides statistics about email attachments, and the second section provides statistics about embedded URLs. For details, see the Email Security — Server User Guide.

    • The gen-emps-rpt CLI command output provides statistics about email attachments, embedded URLs, and other statistics for the past day, week, month, or three months. For details, see the CLI Command Reference.

    For integrated Central Management System deployments, configure the basic network settings for the Email Security — Server appliance before you add it to the Central Management System appliance. See Initial configuration for details.

    For more effective detection and remediation in integrated Central Management System deployments, do not send FAUDE and AV-Suite DTI service requests through the Central Management System appliance. Instead, send the requests directly to unity.fireeye.com (the preferred method) or through an HTTP proxy. For details, see Changing the active setting for a DTI service or Using an HTTP Proxy for DTI Service Requests.

    After deploying and configuring the Email Security — Server appliance, verify that it is deployed correctly and is able to detect malicious attachments and URLs. See Deployment verification for details.

    Consider temporarily stopping the SMTP interface or MTA process during maintenance activities. See Maintenance support for details.

    If the Email Security — Server appliance has heavy email volume and other processing demands, consider deploying it in MVX hybrid mode. See MVX cluster deployment for details.

  • Deploy the Email Security — Server appliance between the anti-spam gateway and the network's internal mail servers, such as Microsoft Exchange.

  • If you use a cloud-based messaging service (such as Proofpoint, Mimecast, or IronPort), email should be delivered to the Email Security — Server appliance as the next-hop before it reaches the internal mail server.

  • Although the Email Security — Server appliance accepts emails of any size from the network stream, the analysis engines—the Multivector Virtual Execution (MVX) engines—by default analyze emails that are 35 MB or less because many enterprises block larger email messages. You can change the maximum size as needed for your environment. For details, see the Email Security — Server User Guide.