Cisco Cisco Email Security Appliance C170 Guia Do Utilizador
9-9
Cisco IronPort AsyncOS 7.6 for Email Configuration Guide
OL-25136-01
Chapter 9 Anti-Spam
Cisco IronPort
Intelligent Multi-Scan Filtering
Cisco IronPort Intelligent Multi-Scan incorporates multiple anti-spam scanning engines, including
Cisco IronPort Anti-Spam, to provide an intelligent, multi-layer anti-spam solution. This method
provides more accurate verdicts that increase the amount of spam that is caught but without increasing
the false positives rate.
Cisco IronPort Anti-Spam, to provide an intelligent, multi-layer anti-spam solution. This method
provides more accurate verdicts that increase the amount of spam that is caught but without increasing
the false positives rate.
When processed by Cisco IronPort Intelligent Multi-Scan, a message is first scanned by third-party
anti-spam engines. Cisco IronPort Intelligent Multi-Scan then passes the message and the verdicts of the
third-party engines to Cisco IronPort Anti-Spam, which assumes responsibility for the final verdict.
After Cisco IronPort Anti-Spam performs its scan, it returns a combined multi-scan score to AsyncOS.
Combining the benefits of the third-party scanning engines and Cisco IronPort Anti-Spam results in
more caught spam while maintaining Cisco IronPort Anti-Spam’s low false positive rate.
anti-spam engines. Cisco IronPort Intelligent Multi-Scan then passes the message and the verdicts of the
third-party engines to Cisco IronPort Anti-Spam, which assumes responsibility for the final verdict.
After Cisco IronPort Anti-Spam performs its scan, it returns a combined multi-scan score to AsyncOS.
Combining the benefits of the third-party scanning engines and Cisco IronPort Anti-Spam results in
more caught spam while maintaining Cisco IronPort Anti-Spam’s low false positive rate.
You cannot configure the order of the scanning engines used in Cisco IronPort Intelligent Multi-Scan;
Cisco IronPort Anti-Spam will always be the last to scan a message and Cisco IronPort Intelligent
Multi-Scan will not skip it if a third-party engine determines that a message is spam.
Cisco IronPort Anti-Spam will always be the last to scan a message and Cisco IronPort Intelligent
Multi-Scan will not skip it if a third-party engine determines that a message is spam.
Using Cisco IronPort Intelligent Multi-Scan can lead to reduced system throughput. Please contact your
Cisco IronPort support representative for more information.
Cisco IronPort support representative for more information.
This feature is supported on all C-Series and X-Series appliances, except for the C100 appliance.
Note
The Intelligent Multi-Scan feature key also enables Cisco IronPort Anti-Spam on the appliance, giving
you the option of enabling either Cisco IronPort Intelligent MultiScan or Cisco IronPort Anti-Spam for
a mail policy.
you the option of enabling either Cisco IronPort Intelligent MultiScan or Cisco IronPort Anti-Spam for
a mail policy.
Enabling Cisco IronPort Intelligent Multi-Scan and Configuring Global Settings
Overview
You enable Cisco IronPortIntelligent Multi-Scan and modify its global configuration settings using the
Security Services > IronPort Intelligent Multi-Scan and Security Services > Service Updates pages
(GUI) or the
Security Services > IronPort Intelligent Multi-Scan and Security Services > Service Updates pages
(GUI) or the
antispamconfig
and
updateconfig
commands (CLI). The following global settings are
configured:
•
Enable Cisco IronPort Intelligent Multi-Scan globally for the appliance.
•
Configure the maximum size of message to be scanned by Cisco IronPort Intelligent Multi-Scan.
•
Enter a length of time to wait for timeout when scanning a message.
Most users will not need to change the maximum message size to be scanned or the timeout value.
That said, you may be able to optimize the throughput of your appliance by lowering the maximum
message size setting.
That said, you may be able to optimize the throughput of your appliance by lowering the maximum
message size setting.
•
Define and (optionally) enable a proxy server for obtaining Cisco IronPort Intelligent Multi-Scan
rules updates (Security Services > Service Updates). If you define a proxy server to retrieve rules
updates, you can optionally configure an authenticated username, password, and specific port when
connecting to the proxy server.
rules updates (Security Services > Service Updates). If you define a proxy server to retrieve rules
updates, you can optionally configure an authenticated username, password, and specific port when
connecting to the proxy server.
•
Define and (optionally) enable a download server from which to receive Cisco IronPort Intelligent
Multi-Scan rules updates (Security Services > Service Updates).
Multi-Scan rules updates (Security Services > Service Updates).
•
Enable or disable receiving automatic updates to Cisco IronPort Intelligent Multi-Scan rules, and
also specify the update interval.
also specify the update interval.