Cisco Cisco Email Security Appliance C170 Betriebsanweisung
10-5
Cisco AsyncOS 8.0.1 for Email User Guide
Chapter 10 Mail Policies
Message Splintering
Message Splintering
Intelligent message splintering is the mechanism that allows for differing recipient-based content
security rules to be applied independently to message with multiple recipients.
security rules to be applied independently to message with multiple recipients.
Each recipient is evaluated for each policy in the appropriate mail policy table (Incoming or Outgoing)
in a top-down fashion.
in a top-down fashion.
Each policy that matches a message creates a new message with those recipients. This process is defined
as message splintering:
as message splintering:
•
If some recipients match different policies, the recipients are grouped according to the policies they
matched, the message is split into a number of messages equal to the number of policies that
matched, and the recipients are set to each appropriate “splinter.”
matched, the message is split into a number of messages equal to the number of policies that
matched, and the recipients are set to each appropriate “splinter.”
•
If all recipients match the same policy, the message is not splintered. Conversely, a maximum
splintering scenario would be one in which a single message is splintered for each message
recipient.
splintering scenario would be one in which a single message is splintered for each message
recipient.
•
Each message splinter is then processed by anti-spam, anti-virus, DLP scanning (outgoing messages
only), Outbreak Filters, and content filters independently in the email pipeline.
only), Outbreak Filters, and content filters independently in the email pipeline.
illustrates the point at which messages are splintered in the email pipeline.
Table 10-2
Message Splintering in the Email Pipeline
Note
New MIDs (message IDs) are created for each message splinter (for example, MID 1 becomes MID 2
and MID 3). For more information, see the “Logging” chapter in the Cisco IronPort AsyncOS for Email
Daily Management Guide. In addition, the
and MID 3). For more information, see the “Logging” chapter in the Cisco IronPort AsyncOS for Email
Daily Management Guide. In addition, the
trace
function shows which policies cause a message to be
split.
Policy matching and message splintering in Email Security Manager policies obviously affect how you
manage the message processing available on the appliance.
manage the message processing available on the appliance.
Wo
rk
Q
u
e
u
e
Message Filters
(filters)
↓
message for all recipients
Anti-Spam
(antispamconfig, antispamupdate)
E
m
a
il Se
cu
rity Ma
na
ger
Sc
ann
ing
(Per Rec
ipie
n
t)
Messages are splintered immediately after
message filter processing but before anti-spam
processing:
message filter processing but before anti-spam
processing:
message for all recipients
matching policy 1
message for all recipients
matching policy 2
message for all other recipients
(matching the default policy)
Anti-Virus
(antivirusconfig,
antivirusupdate)
Content Filters
(policyconfig -> filters)
Outbreak Filters
(outbreakconfig, outbreakflush,
outbreakstatus, outbreakupdate)
Data Loss Prevention
(policyconfig)
Note
DLP scanning is only performed on
outgoing messages.
outgoing messages.