The Drop analysis mode is used in BCC deployments. In Drop mode, the Email Security — Server appliance extracts a copy of all email traffic from an anti-spam device or MTA gateway. After email attachments and embedded URLs are analyzed, non-malicious emails are discarded.
Malicious emails are moved to the quarantine folder, which only an Email Security — Server administrator can access. The eQuarantine and eAlerts tabs in the Email Security — Server Web UI provide comprehensive information about these emails and analysis results. An administrator can remove the emails from the eQuarantine tab, but cannot release them from the quarantine, because they are only copies of the original emails.
The appliance does not notify the intended recipients that malicious emails were detected. It can send "admin" notices about malicious emails to administrators, and can send "bcc" notices with copies of the malicious emails to forensic analysts. If you want these notices to be sent, you must configure the domain and next-hop settings.
Important
Make sure you are aware of the implications of using Drop analysis mode. See Deployment Considerations for details.
Task list for Drop analysis mode
Perform the following steps to configure the Email Security — Server appliance to operate in Drop analysis mode.
Note
This is the minimal configuration for Drop analysis mode. For information about additional options, see the Email Security — Server User Guide.
Ensure the following:
The appliance is installed for BCC deployment mode. (See the Hardware Administration Guide for details.)
The management interface and network access settings are configured correctly. (See Initial Configuration for details.)
The EMPS_ATTACHMENT_SCAN and EMPS_URL_SCAN licenses are installed and valid. (See License Management for details.)
Enable Drop analysis mode. (See Enabling the Analysis Mode .)
Configure the SMTP interface. (See Configuring the SMTP Interface for details.)
(Optional) Configure notices about malicious emails:
Specify the domain and next-hop addresses to which notices will be sent. (See Configuring Domain and Next-Hop Settings for details.)
Configure the notices. (See Configuring Notices for details.)
Use the
reloadcommand in the CLI configuration mode to reboot the appliance.