Gateway Settings

Prev Next

Enable or disable settings for the Trellix GTI IP reputation feature and SPF filter.

Option definitions

Option

Definition

McAfee GTI IP reputation

IP reputation acts as the first level of protection for your Exchange environment, by safeguarding your Exchange server from unsafe email sources. It enables you to leverage the threat intelligence gathered by Global Threat Intelligence to prevent damage and data theft by blocking the email messages at the gateway, based on the source IP address.

Enable

To block email messages at the gateway, based on the source IP address.

IP reputation threshold

Specify a threshold value to block email messages based on the IP reputation score.

Note

The action will be applied to all IP addresses having a reputation score greater than the selected threshold. All other email messages will be allowed through.

You can allow the legitimate IP addresses that are blocked by the IP reputation threshold settings in the Gateway Settings page by modifying the registry values. After allowing the IP address, emails from the allowed IP address are passed through, regardless of its reputation score.

Important: IP address allowing overrides only the IP reputation threshold settings. TSME further scans the email for corrupt or encrypted content, file filter, content scanning, URL reputation, and anti-malware. If there is a detection, action is taken according to the product configuration.

Before allowing the IP address, Trellix recommends that you verify the reputation score of the IP address from sitelookup for its legitimacy.

Trellix cannot be held liable, if you have any mailboxes that are infected by the allowed IP address.

For more information about configuring IP allowing for IP Agent using the registry, see Trellix Knowledge Base article KB82216.

Action to take

Select either of these options to take an action on an email message, based on the reputation score of the source IP address:

  • Drop connection and Log — To drop the email from the detected source IP address and log the action taken on the item.

  • Reject connection and Log — To reject the email from the source IP, by notifying the sender and log the action taken on the item.

IP Blocking or Allowing

You can block or allow legitimate addresses based on the IP addresses added in the blocked or allowed list.

Enable IP Blocking

You can select the IPs to block at the gateway.

Enable the IPs to Block

Blocks the selected IPs.

Enable IP Allowing

You can select the IPs to allow at the gateway.

Enable the IPs to Allow

Allows the selected IPs.

SPF Filter

Protects your systems from spoofing emails, and you can configure actions on Hard Fail and Soft Fail messages.