Cisco Cisco Email Security Appliance C170 Guía Del Usuario
1-3
Cisco IronPort AsyncOS 7.6 for Email Configuration Guide
OL-26342-01
Chapter 1 Getting Started with the Cisco IronPort Email Security Appliance
Enhancement: RSA Email DLP’s “Quarantine a Copy and Deliver” Option
AsyncOS 7.6 provides an option to quarantine a copy of a message that violates a RSA Email DLP policy
while still delivering the original message.
while still delivering the original message.
See
for more information.
Enhancement: SenderBase Reputation Service Requires an Anti-Spam Feature
Key
Key
Starting in AsyncOS 7.6, an Email Security appliance requires an anti-spam system feature key in order
to use the SenderBase Reputation Service.
to use the SenderBase Reputation Service.
New Feature: DKIM Verification Profiles
AsyncOS 7.6 adds DKIM verification profiles, which are lists of parameters that the Email Security
appliance’s mail flow policies use for verifying DKIM signatures. For example, you can create two
verification profiles, one that allows 30 seconds before a query times out and a second that allows only
3 seconds before a query times out. You can assign the second verification profile to the Throttled mail
flow policy to prevent connection starvation in case of a DDoS.
appliance’s mail flow policies use for verifying DKIM signatures. For example, you can create two
verification profiles, one that allows 30 seconds before a query times out and a second that allows only
3 seconds before a query times out. You can assign the second verification profile to the Throttled mail
flow policy to prevent connection starvation in case of a DDoS.
See the “Email Authentication” chapter in the Cisco IronPort AsyncOS for Email Advanced
Configuration Guide for more information.
Configuration Guide for more information.
Enhancement: New Tags for DKIM Signing Profiles
AsyncOS 7.6 adds a new list of tags to include in DKIM message signatures. You select which tags you
want to include in the signatures when creating a DKIM signing profile. The following tags are available:
want to include in the signatures when creating a DKIM signing profile. The following tags are available:
•
“i” Tag. The identity of the user or agent (e.g., a mailing list manager) on whose behalf the message
is signed.
is signed.
•
“q” Tag. A comma-separated list of query methods used to retrieve the public key.
•
“t” Tag. The timestamp of when the signature was created.
•
“x” Tag. The expiration time of the signature, in seconds. (The option in include “x” tag information
existed in previous versions of AsyncOS 7.6.)
existed in previous versions of AsyncOS 7.6.)
•
“z” Tag. A vertical bar-separated (i.e.,
|
) list of header fields present when the message was signed.
See the “Email Authentication” chapter in the Cisco IronPort AsyncOS for Email Advanced
Configuration Guide for more information.
Configuration Guide for more information.
New Feature: DKIM Signing of System-Generated Messages
AsyncOS 7.6 allows you to choose whether to sign system-generated messages with a DKIM signature.
The types of system-generated message that the Email Security appliance will sign include the
following:
The types of system-generated message that the Email Security appliance will sign include the
following:
•
Cisco IronPort Spam Quarantine notifications
•
Content filter-generated notifications