Tap/Span analysis mode is used in SPAN/TAP deployments. In Tap/Span mode, the Email Security — Server appliance listens passively for SMTP traffic from a network switch with port mirroring capabilities. The switch forwards all SMTP traffic to the Email Security — Server appliance through port 25, and the appliance extracts emails from the raw traffic. After the email attachments and embedded URLs are analyzed, non-malicious emails are discarded.
Copies of malicious emails are moved to the quarantine folder, which only an Email Security — Server administrator can access. The eQuarantine and eAlerts tabs in the Email Security — Server Web UI provide comprehensive information about these emails and analysis results. An administrator can remove the emails from the eQuarantine tab, but cannot release them from the quarantine, because they are only copies of the original emails.
In Tap/Span mode, pether3 is not configured as an SMTP interface. It is instead automatically configured as a loopback interface. When you switch from another analysis mode to Tap/Span and then reboot the appliance, the default loopback settings (IP address 127.0.0.10 and netmask 255.255.255.0) are reset.
You can enable the appliance to send another email to notify the intended recipient that a malicious email was detected. Otherwise, the appliance does not notify the intended recipients that malicious emails were detected. It can use the management (ether1) interface to send "admin" notices about malicious emails to administrators, and to send "bcc" notices with copies of the malicious emails to forensic analysts. If you want these notices to be sent, you must configure the domain and next-hop settings.
Caution
Do not attempt to change the pether3 interface settings for Tap/Span analysis mode.
Important
Make sure you are aware of the implications of using Tap/Span analysis mode. See Deployment Considerations for details.
Note
The Microsoft Exchange SMTP extension supports message chunking. This feature is available by default on the appliance for the Tap/Span analysis mode only.
Task list for Tap/Span analysis mode
Perform the following steps to configure the Email Security — Server appliance to operate in Tap/Span analysis mode.
Note
This is the minimal configuration for Tap/Span analysis mode. For information about additional options, see the Email Security — Server User Guide.
Ensure the following:
The appliance is deployed in SPAN/TAP mode. (For details, see the Hardware Administration Guide for your Email Security — Server appliance model.)
The management interface and network access settings are configured correctly. (See Initial Configuration for details.)
The EMPS_ATTACHMENT_SCAN and EMPS_URL_SCAN licenses are installed and valid. (See License Management for details.)
Enable Tap/Span analysis mode. (See Enabling the Analysis Mode for details.)
(Optional) Configure notices about malicious emails:
Specify the domain and next-hop addresses to which notices will be sent. (See Configuring Domain and Next-Hop Settings for details.)
Configure the notices. (See Configuring Notices for details.)
Use the
reloadcommand in the CLI configuration mode to reboot the appliance.