Monitor analysis mode

Prev Next

Monitor analysis mode is one of the two analysis modes that can be used in MTA deployments. In Monitor mode, the Email Security — Server appliance receives emails from an anti-spam device or MTA gateway.

The appliance forwards all emails (including malicious emails) to the next-hop for delivery to the intended recipients. It then analyzes the email attachments and URLs in copies of the emails.

An exception is when the X-Header feature is enabled. In this case, there is a delay in forwarding the emails. The Email Security — Server appliance first analyzes the emails and replaces the default X-Trellix: Not Scanned header message with the appropriate message (for example, X-Trellix: Malicious URL Found, X-Trellix: Clean, and so on). It then forwards the emails to the next-hop for delivery to the intended recipients.

Copies of malicious emails are moved to the quarantine folder, which only an Email Security — Server administrator can access. The eQuarantine and eAlerts tabs in the Email Security — Server Web UI provide comprehensive information about the malicious emails and analysis results. An administrator can remove the emails from the eQuarantine tab, but cannot release them, because they are only copies of the original emails.

In Monitor analysis mode, the appliance does not notify recipients that the emails it forwarded are malicious. It can send "admin" notices about malicious emails to administrators, and can send "bcc" notices with copies of the malicious emails to forensic analysts.

Important

Make sure you are aware of the implications of using Monitor analysis mode. See Deployment Considerations for details.

Task list for monitor analysis mode

Perform the following steps to configure the Email Security — Server appliance to operate in Monitor analysis mode.

Note

This is the minimal configuration for Monitor analysis mode. For information about additional options, see the Email Security — Server User Guide.

  1. Ensure the following:

    • The appliance is deployed in MTA mode. (See the Hardware Administration Guide for details.)

    • The management interface and network access settings are configured correctly. (See Initial Configuration for details.)

    • The EMPS_ATTACHMENT_SCAN and EMPS_URL_SCAN licenses are installed and valid. (See License Management for details.)

  2. Enable the Monitor analysis mode. (See Configuring the Analysis Mode for details.)

  3. Configure the SMTP interface. (See Configuring the SMTP Interface for details.)

  4. Specify the domain and next-hop addresses to which emails will be sent. (See Configuring Domain and Next-Hop Settings for details.)

  5. (Optional) Configure notices about malicious emails. (See Configuring Notices for details.)

  6. Use the reload command in the CLI configuration mode to reboot the appliance.