Cisco Cisco Email Security Appliance C160 Guía Del Usuario
26-32
Cisco AsyncOS 9.5 for Email User Guide
Chapter 26 LDAP Queries
Configuring AsyncOS for SMTP Authentication
This feature is also displayed when editing any mail flow policy in the GUI, providing that LDAP queries
have been configured on the corresponding listener:
have been configured on the corresponding listener:
Figure 26-10
DHAP Prevention Feature in GUI
Entering a number of invalid recipients per hour enables DHAP for that mail flow policy. By default, 25
invalid recipients per hour are allowed for public listeners. For private listeners, the maximum invalid
recipients per hour is unlimited by default. Setting it to “Unlimited” means that DHAP is not enabled
for that mail flow policy.
invalid recipients per hour are allowed for public listeners. For private listeners, the maximum invalid
recipients per hour is unlimited by default. Setting it to “Unlimited” means that DHAP is not enabled
for that mail flow policy.
Configuring AsyncOS for SMTP Authentication
AsyncOS provides support for SMTP authentication. SMTP Auth is a mechanism for authenticating
clients connected to an SMTP server.
clients connected to an SMTP server.
The practical use of this mechanism is that users at a given organization are able to send mail using that
entity’s mail servers even if they are connecting remotely (e.g. from home or while traveling). Mail User
Agents (MUAs) can issue an authentication request (challenge/response) when attempting to send a
piece of mail.
entity’s mail servers even if they are connecting remotely (e.g. from home or while traveling). Mail User
Agents (MUAs) can issue an authentication request (challenge/response) when attempting to send a
piece of mail.
Users can also use SMTP authentication for outgoing mail relays. This allows the appliance to make a
secure connection to a relay server in configurations where the appliance is not at the edge of the
network.
secure connection to a relay server in configurations where the appliance is not at the edge of the
network.
AsyncOS supports two methods to authenticate user credentials:
•
You can use an LDAP directory.
•
You can use a different SMTP server (SMTP Auth forwarding and SMTP Auth outgoing).
Figure 26-11
SMTP Auth Support: LDAP Directory Store or SMTP Server
Configured SMTP Authentication methods are then used to create SMTP Auth profiles via the
smtpauthconfig
command for use within HAT mail flow policies (see
Enter the maximum number of invalid recipients per hour from a remote host.
[25]>