Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Content Filtering Rules / Policies -- What do you have setup?? 1

Status
Not open for further replies.

MRoberto

IS-IT--Management
May 9, 2005
41
0
0
US
Hello all

I am trying to get a feel for how other users of Norton/Symantec Email Security have their policies setup.

Basic Virus scanning:

Unscannable File Rule --> Delete or quarantine?
Encrypted File Rule --> Delete or quarantine?

basic outbreak settings?

ANTIVIRUS SETTINGS:
Basic file rule --> delete entire message?
Unrepairable file rule --> delete entire message?
Security Risk rule --> enabled? --? delete or quarantine?

HEURISITIC DETECTION:

SCL settings? Reject messages? Prevent Delivery?


CONTENT FILTERING:

blocked attachments?
-- block all and allow exceptions?
-- allow all and block exceptions?
--quarantine or delete??

blocked subjects?
-- use default match lists?
-- quarantine or delete?

blocked message body?
-- quarantine or delete?

I am using the newest version of SMSMSE 5.0.3

During installation of the program, my collegues who installed the thing without me turned on the default content filtering rules that come with the program, enabled them, and didnt bother to look at them.

The very first night after install, SMSMSE was told to scan the entire message store (all of our users mailboxes) and quarantine any attachment on any email that wasnt a .doc .xls .ppt .pdf .rtf or .txt file. So basically any other type of attachment was grabbed and quarantined in our entire email store.

What happened was, we had over 5k items in quarantine, with no way to restore the items to the original emails.

We have decided to release all to an admin email box, and will have to do digging if anyone ever asks us why they cant lookup an old or archived attachment.

Anyways, I'm trying to remedy the problem and setup this program the way it should be working.

We did not get the premium anti-spam add-on yet but i am pushing for it.

I really do not like the way Symantec offers both information about blocked and quarantined items (not enough info to show you exactly WHY it was blocked, what words caused the errors) and also how they offer so few options to un-do a quarantine.

I would love to hear feedback about nightmare stories about the product, and also recommendations about content filtering policies, and also whatever else you may have to say.

Mike in FLA

 
Unfortunately I had exactly the same scenario happen. Entire Calendars were wiped clean in exchange/outlook. I cannot believe the default settings did not allow for those types of file extensions and I cannot believe that there is no way to restore the files. This has been the most frustrating and embarrassing events I have ever had happen to me since working in this field!
 
Yes I hear you. I do not feel as bad because it was my boss and the level 2 analyst who installed the thing. I probably could have gotten fired for something like that. It is pretty sad that Symantec pushed out their product that way though.

Did you have a bunch of attachments get Quarantined as well, or did you mainly just have a problem with calendars? If it was just calendars, couldn't you have restored just the calendar settings from a backup from the night before or something?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top