Руководство Пользователя для Cisco Cisco Email Security Appliance C170

Скачать
Страница из 630
12-399
Cisco IronPort AsyncOS 7.1 for Email Configuration Guide
OL-22158-02
Chapter 12      IronPort Email Encryption
message or send it over a TLS connection based on the TLS setting in the 
destination controls (Required, Preferred, or None) and the action defined in the 
encryption content filter.
When creating the content filter, you can specify whether to always encrypt a 
message or to attempt to send it over a TLS connection first, and if a TLS 
connection is unavailable, to encrypt the message. 
 shows you how an 
Email Security appliance will send a message based on the TLS settings for a 
domain’s destination controls, if the encryption control filter attempts to send the 
message over a TLS connection first.
For more information on enabling TLS on destination controls, see the 
“Customizing Listeners” chapter in the Cisco IronPort AsyncOS for Email 
Advanced Configuration Guide
.
Creating a Content Filter to Encrypt and Deliver Now
To create a content filter to encrypt a message and deliver it immediately, skipping 
any further processing:
Step 1
Go to Mail Policies > Outgoing Content Filters.
Step 2
In the Filters section, click Add Filter.
Step 3
In the Conditions section, click Add Condition.
Step 4
Add a condition to filter the messages that you want to encrypt. For example, to 
encrypt sensitive material, you might add a condition that identifies messages 
containing particular words or phrases, such as “Confidential,” in the subject or 
body.
Table 12-2
TLS Support on ESA Appliances
Destination Controls TLS 
Setting
Action if TLS Connection 
Available
Action if TLS Connection 
Unavailable
None
Encrypt envelope and 
send
Encrypt envelope and 
send
TLS Preferred
Send over TLS
Encrypt envelope and 
send
TLS Required
Send over TLS
Retry/bounce message