Jump to content

Recommended Posts

Posted

Hi,

 

What EMail Content Filtering software/appliances are people using? Note that I'm talking content filtering for email.

 

Are you manually configuring Exchange 2007/2010 to do this?

OR

Are you using an extra piece of software or physical appliance?

 

We've just been looking at the SonicWall EMail Security Appliance, but once you've added up the user licenses, maintenance etc it gets a little too pricey.

 

Thanks, Dan

Posted

You can use FPE 2010 for Exchange 2007/2010. Probably get a discount if you have some MSFT licensing programme you're committed to.

 

 

 

Sukh

Posted
I'm shifting our Messagelabs to Forefront Online Protection for Exchange, if you're on EES \ Campus check your entitlements as you might already have it on there :)
Posted

Thanks to all replies, doesn't seem to be any single product that 'everyone' is using.

 

@GrumbleDook, filtering of all emails, inbound/outbound and between users. I believe that we must provide filtering between users to catch any bullying that may take place via email.

Posted
mimsweeper has deep user email scanning and can pick out certain keywords and can even send copies of emails to a different address like an admin email, I think also we had it running on facebook messages / chat.
Posted

For internal email scanning, products such as FPE can catch emails with profanity and custom keywords etc as well as performing AV and AS. This will probably be a cheap option if your have some MSFT agreement.

 

As for external emails coming into your gateway, or from your gateway to your exchange server, I'd recommend a subscription like messagelabs. You ideally want to catch as much spam/av before anything gets to your gateway/exchange org and then have anm additional layer at the gateway/exchange.

 

For gateways, I'd recommend Ironport or clearswift. If you do decide to go with clearswift then do go for the CSEG's, I.e appliances rather than the software. However, using these products can be expensive.

 

Sukh

Posted

@CyberNerd - postini are good and did really well in the US. They have a fairly good market in the UK too. I have used them in the pass for many customers and are a way cheaper than ML, however, when it comes to AS/AV, they use engines like most tier 2 AV providers, whereas ML actually (well now called symantec.cloud) have advanced engines and create and distribute potential AV to tier 2.

 

Another intelligent product is Brightmail which is really good.

 

Sukh

Posted

If Smoothwall does filtering via SMTP then there's a way to get your exchange box to send internal email out to the SMTP (routing agent to rewrite address) - and if the Smoothwall is then able to rewrite addresses it can be delivered back in...

 

That's the way we currently handle internal to internal mail with the County's mail filtering platform :)

Posted

I thought SmoothZap was the Smoothie offering for e-mail scanning and filtering?

 

Could be wrong but i thought it was :)

Posted

@Willott - This may work, extra routing just to get internal email screened, and extra overhead on all servers and devices along the route. I'd recommend using a product with your Exchange org rather than route out the Smoothwall and rewrite addresses.

 

Sukh

Posted (edited)
@Willott - This may work, extra routing just to get internal email screened, and extra overhead on all servers and devices along the route. I'd recommend using a product with your Exchange org rather than route out the Smoothwall and rewrite addresses.

 

Sukh

 

Depends on how big your Exchange org is, volume of emails, cost of filtering products, how your servers are spec'd etc etc

 

We do it this way as email filtering is part of the service provided to us by County. So we don't have to pay for further filtering and don't have to worry about the extra load on the Exchange server (the load or rewriting an address compared with the load of scanning an email is negligible) that would be seen with an on server scanning solution.

 

With this way round, there can be servers optimized for spam/virus scanning and servers optimized for Exchange. For everything else we look to split roles to provide best performance, reliability, resilience and configurability, so why change that for email hosting and scanning?

 

It also seems to be the way that one of the "providers" for education have their Exchange Org setup, as this is the way both our County and previous RBC are setup.

Edited by Willott
Posted
I thought SmoothZap was the Smoothie offering for e-mail scanning and filtering?

 

Could be wrong but i thought it was :)

Nope.

 

Content Analysis

(Mailshell 3.0 SpamContent)

 

Reputation Checking (using Mailshell Spam Detection Network & Bayesian analysis)

 

Bulk Mail Detection (Mailshell SpamBulk)

 

Phishing Protection (Mailshell SpamTricks)

 

VIPRE Anti-Virus Engine

 

Do you have any information on that Willot? I suspect you use Webroot SaaS too.

  • Thanks 1
Posted

@Willott - It does depend on a number of factors. If inbound emails are screen by your county, then you have one layer of defense. To route emails from your Exchange Org to Smoothwall and then do address-rewrite, can cause issues. I know you say you have this running, but I haven't seen this type of set-up before, except for relays within your AD which may be relaying from a SMTP server with no AV/AS.

 

Having AV/AS on the Exchange Server can also provide additional checks/scans on the mailstores themselves. What if an email in your mailbox is effected with a virus, or in your store? What if you use PF databases are infected?

 

When one specs servers for Exchange, I would expect one to spec the server with AV in mind. And AV on Exchange servers isn't as intensive as one may thing, it depends on a number of configurations, engines used.

 

I suppose one can save money with your config but the cost for say FPE 2010 under the EES is not much. Also, in my opinion, this is not best practise for internal email scanning.

 

But your solution can work.

 

Sukh

Posted
Do you have any information on that Willot? I suspect you use Webroot SaaS too.

 

No info on that I'm afraid - used to be on Webroot but now it's Mailmarshal... seems to be roughly the same setup between the two. It looks like Smoothwall's new offering is still off Exchange box, so should work in the same way should you want to use for internal-internal filtering.

 

Cheers

 

Will

Posted
Nope.

 

Content Analysis

(Mailshell 3.0 SpamContent)

 

Reputation Checking (using Mailshell Spam Detection Network & Bayesian analysis)

 

Bulk Mail Detection (Mailshell SpamBulk)

 

Phishing Protection (Mailshell SpamTricks)

 

VIPRE Anti-Virus Engine

 

Do you have any information on that Willot? I suspect you use Webroot SaaS too.

 

Fair nuff :) I stand corrected!

Posted

Currently use the LAs scanning on the incoming and outgoing, but that will cease fairly soon (hozzah!) and we will move onto Smoothzap for the mail filtering :) Looking forward to testing that out as its about the only bit of it I've never used!

 

For keeping an eye on internal stuff, we have some transport rules setup to monitor kids emails, any word on the custom lists I have set get sent for approval to a language monitoring mailbox, this is accessible by Heads of House and SLT, they can then choose to approve the email if its blocked by accident or delete the email and then deal with the issue at that time. Works rather well so far but only as good as my custom lists which soon get out of date :(

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...