Configuring Email Connector

Prev Next

Email Connector protects you from email borne threats by analyzing email attachments and URLs starting with http, https and ftp in the body of the email, through Intelligent Sandbox.

Note

  • Email Connector is not installed with Intelligent Sandbox. You need to install Email connector separately using systemex-5.x.x.xx.xxxxx.msu. For more information on installing Email Connector, see Install Email Connector.

  • If you have configured a cluster, ensure that you install Email connector in your primary as well as the backup nodes.

  • Ensure that you have reset your cliadmin password. If you continue using the default password, the configurations will fail.

  • In order to utilize the URL scanning option, as a prerequisite,

    1. Install the latest systemex provided for 5.0 release.

    2. Enable the Enable Malware Internet Access checkbox in the analyzer profile associated with atdec user.

  • Intelligent Sandbox accepts up to 100 URLs per email for analysis.

  • Email Connector URL scanning is configurable from 4.12.2 release. Refer the below procedure to enable/disable this in Intelligent Sandbox:

    1. In 4.12.0, URL scanning is enabled by default.

    2. Install the latest systemex provided for 5.0 release.

    3. Post upgrade, URL scanning gets disabled.

    4. From ATD UI Page, Go to Manage | Email Connector | under Scanning Email | Configuration.

    5. Check the URL Analysis checkbox.

    6. Click Apply to enable it again.

Intelligent Sandbox receives emails from a secure email gateway, performs an analysis on the email attachments and URLs in the body of the email, adds a verdict in the email header and sends it back to the email server.

You need to configure your email gateway to send emails to the Intelligent Sandbox for analysis. You can add filters such as send the ones with attachment only and so on. We recommend you configure your SEG to send emails for analysis to Intelligent Sandbox only when your SEG's AV analysis have returned an inconclusive result.

Troubleshooting email connector

You can also view the conversation log for each email report when you click GUID-B5B4CEAC-0E1F-4067-9ABA-8A273A2EFCFF-low.png under the Log column. The HTML or PDF reports for a sample now displays the Received Time in UTC time zone. Previously the HTML or PDF reports displayed the time stamp in the local time-zone.

Note

  • While you view the reports, the maximum number of reports you can navigate to are one million. If you want to view the reports beyond one million, use the search filter to reduce the result of the number of reports.

  • The updated time might take few minutes to reflect in the reports page post migration. This is dependent on the size of the reports database.