08-15-2007 05:22 PM
When to use "Continue" Connection behavior in mail flow policies?
What's the difference between "Continue" and "Accept"?
08-16-2007 07:39 PM
When to use "Continue" Connection behavior in mail flow policies?
What's the difference between "Continue" and "Accept"?
Order Sendergroup Mail Flow Policy
====== ============= =================
1 RELAYLIST RELAYED (relay)
2 WHITELIST TRUSTED (accept)
3 BLACKLIST BLOCKED (reject)
4 SUSPECTLIST (-3 to 0) THROTTLED (continue)
5 UNKNOWNLIST ACCEPTED (accept)
ALL ACCEPTED (accept)
08-16-2007 07:49 PM
Also, some folks may wonder what's the difference between REJECT and TCPREFUSE in the connection behavior of the mail flow policies. This was taken from the Support Portal knowledge base
(http://www.ironport.com/support), then click on Support Portal on the left side.
What is the difference between REJECT and TCPREFUSE?
You can configure your Email Security Appliance (ESA) to restrict connections by adding any of the following items to Sender Groups which use Mail Flow Policies:
Each Mail Flow Policy has an access rule, such as ACCEPT, REJECT, RELAY, CONTINUE, and TCPREFUSE.
A host that attempts to establish a connection to your ESA and matches a Sender Group using a TCPREFUSE access rule is not allowed to connect to your ESA. From the standpoint of the sending server, it will appear as if your server is unavailable. Most MTA's will retry frequently in this case.
A host that attempts to establish a connection to your ESA and encounters a REJECT will receive a 554 SMTP error (hard bounce).
For most implementations REJECT is a better policy as the sending ESA knows instantly that your domain will not accept messages from them. This not only reduces overall load on your appliance, but the sender recives a Non Deliverable Report (NDR) immediately instead of waiting for the retries to expire, which can take as long as five days for some senders. If the sender was erroneously blocked, this can be useful.
$REFERENCES
AsyncOS User Guide: Access Rules and Parameters
http://support.ironport.com/docs/c_series/4.0/user_guide/AsyncOS_4.0_User_Guide_for_C-Series-10-3.html
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: