Cisco Cisco Email Security Appliance C160 Mode D'Emploi

Page de 460
 
6-35
Cisco IronPort AsyncOS 7.6 for Email Configuration Guide
OL-25136-01
Chapter 6      Email Security Manager
Figure 6-23
Updated Content Filters for Incoming Mail Policies
Step 5
Commit your changes.
At this point, incoming messages that match the user list for the engineering policy will not have MP3 
attachments stripped; however, all other incoming messages will have MP3 attachments stripped. 
Notes on Configuring Content Filters in the GUI
  •
It is not necessary to specify a condition when creating a content filter. When no action is defined, 
any actions defined will always apply in the rule. (Specifying no action is   equivalent to using the 
true()
 message filter rule — all messages will be matched if the content filter is applied to a policy.) 
  •
If you do not assign a custom user role to a content filter, the content filter is public and can be used 
by any delegated administrator for their mail policies. See the “Common Administrative Tasks” in 
the Cisco IronPort AsyncOS for Email Daily Management Guide for more information on delegated 
administrators and content filters.
  •
Administrators and operators can view and edit all content filters on an appliance, even when the 
content filters are assigned to custom user roles.
  •
When entering text for filter rules and actions, the following meta characters have special meaning 
in regular expression matching: 
. ^ $ * + ? { [ ] \ | ( )
If you do not wish to use regular expression you should use a '\' (backslash) to escape any of these 
characters. For example: "\*Warning\*" 
  •
When you define more than one Condition for a content filter, you can define whether all of the 
defined actions (that is, a logical AND) or any of the defined actions (logical OR) need to apply in 
order for the content filter to be considered a match. 
Figure 6-24
Choosing Any or All of the Following Conditions
  •
You can test message splintering and content filters by creating “benign” content filters. For 
example, it is possible to create a content filter whose only action is “deliver.” This content filter 
will not affect mail processing; however, you can use this filter to test how Email Security Manager 
policy processing affects other elements in the system (for example, the mail logs). 
  •
Conversely, using the “master list” concept of the Incoming or Outgoing Content Filters, it is 
possible to create very powerful, wide-sweeping content filters that will immediately affect message 
processing for all mail handled by the appliance. The process for this is to: