Enable Email Connector and configure options for the Secure Email Gateway (SEG) from where the emails are received, file analysis settings, and destination SEG or relay hosts to which the emails with analysis headers are forwarded.
Log on to the Intelligent Sandbox interface, then click → → .
In Email Connector Configuration, select Enable Email Connector, and then choose:
Inline Mode (hold email until decision made) – Emails are delivered to an onward SEG or MTA after Intelligent Sandbox scan.
Offline Mode (send copy of email to ATD for analysis) – Emails are discarded from Intelligent Sandbox after a scan. The email and analysis reports are maintained on Intelligent Sandbox.
Note
Relay host need not be configured if you choose Offline Mode.
In Receiving Email, complete these settings.
Listen Port — Type the port number to use for receiving emails. The default port number is 25.
Use TLS Connection — Select the level of security in TLS communication between ATD and the SEG that sends the emails. Choose from the three options to use TLS-secured communication, for receiving emails.
Permitted Hosts — From the drop-down, select the Host type as IP address, Hostname, or Network, then enter the IP addresses, host name, or network address of the source SEG for Intelligent Sandbox to receive emails. Click Add to add a Permitted host.
In Sending Email, complete these settings.
You can configure multiple relay hosts—where with multiple domains, you can configure a specific relay host for each domain.
In Use TLS Connection, select when to use TLS-secured communication for all outbound emails.
In Relay Host Value, type the IP address or hostname of the destination email server.
In Port, type the port number of the destination email server.
In Domain, type the domain name of the domain that you want this host to handle.
Note
If you want to configure a default relay host, enter * for the domain name.
Ensure that the default relay host is the last relay host you add. This keeps it as the last item of the list. If the default relay host is on the top of the list, all emails are sent to this relay host, and the remaining relay hosts in the list are ignored.
Ensure that you have configured a DNS server that can resolve this domain name and the hostname (if set) that is set in Relay Host Value..
Click Add, to add the relay host.
The relay host would now appear in the list. Repeat Steps b, c, and d to add more relay hosts.
In Scanning Email, complete these settings.
Maximum time per email to wait for all scans to complete — The maximum time (in seconds) within which the analysis must complete. The analysis times-out when the time exceeds the time specified and the email is queued in the SEG. Default is 600.
Scan these file types — Select the file types of the email attachments to scan.
Skip Protected Files — Ignores protected files during the scan.
Action when system is overloaded — Choose whether to deliver emails without scanning or drop SMTP connections when the system is overloaded.
Note
If you have selected Deliver emails unscanned, then the emails are delivered with the X-ATD-VERDICT as -8.
URL Analysis — By default, this setting is disabled. When enabled, the URLs in the email are detected and sent to ATD for analysis. The URL's severity plays an important role in determining the overall severity of the email.
Sandbox all URLs — This checkbox is available for configuration only if the URL Analysis setting is enabled. URLs that are classified as clean by GTI URL are sent to sandbox for analysis only when this check box is enabled. For the URLs detected in the email, the value of this check box takes precedence over the Continue to run all engines even after file is found malicious check box in the analyzer profile associated with 'atdec' user. When the Continue to run all engines even after file is found malicious check box is enabled and the Sandbox all URLs check box is disabled, the URL, if clean, is not sent to sandbox for analysis.
In Attachment Profiling, complete these settings.
Enable Profiling Mode (Attachments and URLs will not be scanned in this mode) – Enables email profiling. This option disables scanning the email attachments and URLs. Only email count is incremented and sent to the transporting email server.
Note
If you enable this option, the header X-ATD-VERDICT -7 is added to the emails.
Document Format – Select the format in which you want your profiling report to get generated.
Reporting Period – Select the period for which you want the emails to be profiled.
Granularity – Select the period in a granular level.
Download Report – Downloads the email profiling report. This option is available only if you have enabled email profiling mode.
Click Apply.
You can view the total number of emails and attachments/URLs analyzed in the Email Counter monitor from the Dashboard.