Fortishield; Fortishield Spam Filtering - Fortinet FortiGate FortiGate-5001 Administration Manual

Fortigate 5000 series
Hide thumbs Also See for FortiGate FortiGate-5001:
Table of Contents

Advertisement

Spam filter

FortiShield

FortiShield Spam filtering

FortiGate-5000 series Administration Guide
Order of spam filter operations
Generally, incoming email is passed through the spam filters in the order the filters
appear in the spam filtering options list in a firewall protection profile (and in
FortiShield, IP address, DNSBL & ORDBL, HELO DNS lookup, email address, return
email DNS check, MIME header, and banned word (content block). Each filter passes
the email to the next if no matches or problems are found. If the action in the filter is
Mark as Spam, the FortiGate unit will tag or discard (SMTP only) the email according
to the settings in the protection profile. If the action in the filter is Mark as Clear, the
email is exempt from any remaining filters. If the action in the filter is Mark as Reject,
the email session is dropped. Rejected SMTP email messages are substituted with a
configurable replacement message. See
The order of spam filter operations may vary between SMTP and IMAP or POP3 traffic
because some filters only apply to SMTP traffic (IP address and HELO DNS lookup).
Also, filters that require a query to a server and a reply (FortiShield and
DNSBL/ORDBL) are run simultaneously. To avoid delays, queries are sent while other
filters are running. The first reply to trigger a spam action will take effect as soon as
the reply is received.
This chapter describes:
FortiShield
IP address
DNSBL & ORDBL
Email address
MIME headers
Banned word
Using Perl regular expressions
You can filter Spam with an IP address black list and a URL black list using the
Fortinet FortiShield product.
This section describes:
FortiShield Spam filtering
FortiShield options
Configuring the FortiShield cache
FortiShield CLI configuration
FortiShield is an antispam system from Fortinet that includes an IP address black list,
a URL black list, and spam filtering tools. The IP address black list contains IP
addresses of email servers known to be used to generate Spam. The URL black list
contains URLs of website found in Spam email.
01-28008-0013-20050204
"Replacement messages" on page
FortiShield
Table
31):
114.
335

Advertisement

Table of Contents
loading

Table of Contents