Transcription of Trend Micro, Incorporated reserves the right to make ...
1 Trend micro , Incorporated reserves the right to make changes to this document and to the products described herein without notice. Before installing and using the software, please review the readme files, release notes, and the latest version of the applicable user documentation, which are available from the Trend micro Web site at: micro , the Trend micro t-ball logo, InterScan, and Trend micro Control Manager are trademarks or registered trademarks of Trend micro , Incorporated . All other product or company names may be trademarks or registered trademarks of their 2003-2009 Trend micro , Incorporated . All rights reserved. Document Part No. MSEM74175/90727 Release Date: November 2009 Patents PendingThe user documentation for Trend micro InterScan Messaging Security Suite is intended to introduce the main features of the software and installation instructions for your production environment.
2 Read it before installing or using the software. Detailed information about how to use specific features within the software are available in the online help file and the online Knowledge Base at Trend micro s Web site. Trend micro is always seeking to improve its documentation. Your feedback is always welcome. Please evaluate this documentation on the following site: .. xiiInterScan Messaging Security Suite Documentation .. xiiDocument Conventions .. xiiiChapter 1: Getting StartedOpening the IMSS Web Management Console .. 1-2 Using the Online Help .. 1-3 Viewing the Web Management Console Using Secure Socket Layer .. 1-3 Tools for Creating the SSL Certificate .. 1-3 Creating an SSL Certificate.
3 1-4 Performing Basic Configuration with the Configuration Wizard .. 1-5 Accessing the Configuration Wizard .. 1-5 Changing the Management Console Password .. 1-14 Updating Scan Engine and Pattern Files .. 1-15 Specifying an Update Source .. 1-16 Performing a Manual Update .. 1-18 Rolling Back a Component Update .. 1-19 Configuring Scheduled Update .. 1-19 IMSS Services .. 1-21 Starting or Stopping Services .. 1-22 Opening the End-User Quarantine Console .. 1-23 Logon Name Format .. 1-23 Trend micro InterScan Messaging Security Suite Administrator s GuideivChapter 2: Configuring IMSS SettingsIP Filtering Service .. 2-2 Using Email Reputation .. 2-2 Using the SPS Activation Code .. 2-2 Using the Email Reputation Management Console.
4 2-3 Configuring IP Filtering .. 2-7 Step 1: Enabling Email Reputation and IP Profiler .. 2-7 Step 2: Adding IP Addresses to the Approved List .. 2-9 Step 3: Adding IP Addresses to the Blocked List .. 2-9 Step 4: Enabling IP Profiler Rules ..2-10 Step 5: Configuring Email Reputation ..2-15 Displaying Suspicious IP Addresses and Domains ..2-18 Scanning SMTP Messages ..2-19 Configuring SMTP Routing ..2-19 Configuring SMTP Settings ..2-19 Configuring Connections Settings ..2-20 Configuring Message Rule Settings ..2-23 About Domain-Based Delivery ..2-26 Configuring Delivery Settings ..2-26 About Transport Layer Security ..2-32 IMSS Support of Transport Layer Security ..2-33 Configuring Transport Layer Security Settings.
5 2-34 Configuring Transport Layer Security Settings for Messages Entering IMSS ..2-34 Adding Trusted CA Certificates for Messages Entering IMSS ..2-37 Configuring Transport Layer Security Settings for Messages Exiting IMSS ..2-38 Adding Trusted CA Certificates for Messages Exiting IMSS ..2-40 Scanning POP3 Messages ..2-41 Understanding POP3 Scanning ..2-41 Requirements ..2-42 Enabling POP3 Scanning ..2-42 Configuring POP3 Settings ..2-44 ContentsvChapter 3: Managing PoliciesManaging Policies .. 3-2 How the Policy Manager Works .. 3-2 Configuring Policy Objects .. 3-4 Understanding Address Groups .. 3-6 Creating Address Groups .. 3-7 Editing or Deleting an Address Group .. 3-11 Exporting an Address Group.
6 3-13 Using BATV Keys .. 3-14 Adding BATV Keys .. 3-15 Viewing BATV Keys .. 3-17 Using the Keyword & Expression List .. 3-17 Configuring an Expression .. 3-18 Using the Notifications List .. 3-21 Adding or Modifying a Policy Notification .. 3-22 Using Stamps .. 3-25 Creating Stamps .. 3-25 Using the DKIM Approved List .. 3-27 Using the Web Reputation Approved List .. 3-29 Adding to the Web Reputation Approved List .. 3-29 Configuring Internal Addresses .. 3-31 Searching for an LDAP User or Group .. 3-33 Adding Policies .. 3-35 Specifying a Route .. 3-36 Configuring the Route .. 3-41 Configuring Exceptions for Routes .. 3-42 Specifying Scanning Conditions .. 3-43 Selecting Scanning Conditions for Spam.
7 3-49 Configuring Approved and Blocked Sender Lists .. 3-50 Configuring Spam Text Exemption Rules .. 3-51 Configuring Web Reputation Settings .. 3-52 Selecting Scanning Conditions for Attachments .. 3-53 Selecting Scanning Conditions for Message Size .. 3-55 Selecting Scanning Conditions for Message Content .. 3-56 Trend micro InterScan Messaging Security Suite Administrator s GuideviSpecifying "Other" Scanning Conditions ..3-56 Selecting Scanning Conditions for Number of Recipients ..3-57 Setting Scanning Conditions for Message Arrival Time ..3-57 Specifying Actions ..3-58 Creating a Tag Subject ..3-66 Finalizing a Policy ..3-66 Modifying Existing Policies ..3-68 Using the Domain List for the Global DKIM Enforcement Rule.
8 3-69 Using the Domain and Email Exclusion List for the Global BATV Rule ..3-70 Policy Example 1 ..3-72 Policy Example 2 ..3-75 Using the Asterisk Wildcard ..3-79 Setting Scan Exceptions ..3-80 Configuring Exceptions for Security Settings Violations ..3-81 Setting Scan Actions for Security Setting Violations ..3-82 Setting Scan Actions for Malformed Messages Scanning Exceptions ..3-83 Chapter 4: Backing Up, Restoring, and Replicating SettingsImporting/Exporting Settings .. 4-2 Backing Up IMSS .. 4-3 Restoring IMSS .. 4-5 Replicating Settings ..4-10 Enabling Control Manager Agent ..4-11 Replicating Settings from Control Manager ..4-12 ContentsviiChapter 5: Monitoring the NetworkMonitoring Your Network.
9 5-2 Viewing Statistics Summary .. 5-2 Viewing System Summary .. 5-3 Interpreting the Statistics .. 5-4 Performance Overview .. 5-5 Scan Performance .. 5-5IP Filtering Performance .. 5-6 Generating Reports .. 5-8 Types of Report Content .. 5-8 Managing One-time Reports .. 5-9 Adding One-time Reports .. 5-10 Using Scheduled Reports .. 5-13 Configuring Scheduled Reports .. 5-14 Logs .. 5-17 Configuring Log Settings .. 5-17 Querying Logs .. 5-19 Mail Areas and Queues .. 5-25 Configuring Quarantine and Archive Settings .. 5-25 Managing Quarantine Areas .. 5-26 Managing Archive Areas .. 5-29 Querying Messages .. 5-31 Viewing a Quarantined Message .. 5-35 Viewing Archived Messages .. 5-36 Viewing Deferred Messages.
10 5-37 Configuring User Quarantine Access .. 5-38 Adding/Removing an EUQ Database .. 5-40 Adding an EUQ Database .. 5-40 Removing an EUQ Database .. 5-42 Command-line Options for euqtrans Tool .. 5-42 Event Notifications .. 5-43 Configuring Delivery Settings .. 5-44 Configuring Event Criteria and Notification Message .. 5-47 Configuring Web EUQ Digest Settings .. 5-48 Editing Notifications .. 5-49 Trend micro InterScan Messaging Security Suite Administrator s GuideviiiChapter 6: Using End-User QuarantineAbout EUQ .. 6-2 Step 1: Configuring and Enabling LDAP .. 6-2 Step 2: Enabling EUQ .. 6-5 Step 3: Starting the EUQ Service .. 6-6 Step 4: Enabling End-User Access .. 6-6 Step 5: Opening the End-User Quarantine Console.