config_ip_filtering

Configuring IP Filtering

To configure IP Filtering, perform the following steps:

Step 1: Enabling Email Reputation and IP Profiler

Enable Email reputation and IP Profiler to begin IP Filtering protection. You can enable both or one type of protection.

  1. Choose IP Filtering > Overview from the menu. The IP Filtering Overview screen appears.

  2. Select the Enable IP Filtering check box. This will select both the Email reputation and IP Profiler check boxes.

  3. Clear the Email reputation or IP Profiler check box if you do not require them.

  4. Click Save.

Step 2: Adding IP Addresses to the Approved List

IMSVA does not filter IP addresses or domains that appear in the Approved List.

  1. Choose IP Filtering > Approved List from the menu. The Approved List screen appears.

  2. Click Add. The Add IP/Domain to Approved List screen appears.

  3. Select the Enable check box.

  4. Type the domain or IP address that you would like to add to the Approved List.

  5. Click Save. The domain or IP address appears in the Approved List.

Step 3: Adding IP Addresses to the Blocked List

IMSVA blocks IP addresses that appear in the Blocked List.

  1. Choose IP Filtering > Blocked List from the menu. The Blocked List screen appears.

  2. Click Add. The Add IP/Domain to Blocked List screen appears.

  3. Select the Enable check box.

  4. Type the domain or IP address.

  5. Select Block temporarily or Block permanently.

  6. Click Save. The domain or IP address is added to the blocked list.

Step 4: Enabling IP Profiler Rules

Rules are set to monitor the behavior of all IP addresses and block them according to the threshold setting. Rules can be set for the following:

  1. Choose IP Filtering > Rules from the menu. The Rules screen appears with 4 tabs, one for each type of threat.

  2. Click the Spam tab. The Spam screen appears.

  3. Select the Enable check box to enable blocking of spam.

  4. Specify a value for the following:

  5. Consider the following example.

    Duration to monitor: 1 hour at a rate of 20 out of 100

    During each one-hour period that spam blocking is active, IMSVA starts blocking IP addresses when more than 20% of the messages it receives contain spam and the total number of messages exceeds 100.

  6. Next to Triggering action, select one of the following:

  7. Click Save.

  1. Choose IP Filtering > Rules from the menu. The Rules screen appears with 4 tabs, one for each type of threat.

  2. Click the Virus tab. The Virus screen appears.

  3. Select the Enable check box to enable blocking of viruses.

  4. Configure the following:

  5. Consider the following example.

    Duration to monitor: 1 hour at a rate of 20 out of 100

    During each one-hour period that virus blocking is active, IMSVA starts blocking IP addresses when more than 20% of the messages it receives contain viruses and the total number of messages exceeds 100.

  6. Next to Triggering action, select one of the following:

  7. Click Save.

  1. Choose IP Filtering > Rules from the menu. The Rules screen appears with 4 tabs, one for each type of threat.

  2. Click the DHA Attack tab. The DHA Attack screen appears.

  3. Select the Enable check box to enable blocking of directory harvest attacks.

  4. Configure the following:

  5. Consider the following example.

    Duration to monitor: 1 hour at a rate of 20 out of 100 sent to more than 10 recipients when the number of non-existing recipients exceeds 5.

    During each one-hour period that DHA blocking is active, IMSVA starts blocking IP addresses when it receives more than 20% of the messages that were sent to more than 10 recipients (with more than five of the recipients not in your organization) and the total number of messages exceeds 100.

  6. Click Save.

  1. Choose IP Filtering > Rules from the menu. The Rules screen appears with 4 tabs, one for each type of threat.

  2. Click the Bounced Mail tab. The Bounced Mail screen appears.

  3. Select the Enable check box to enable blocking of bounced mail.

  4. Configure the following:

  5. Consider the following example.

    Duration to monitor: 1 hour at a rate of 20 out of 100

    During each one-hour period that blocking for bounced mail is active, IMSVA starts blocking IP addresses when more than 20% of the messages it receives are bounced messages and the total number of messages exceeds 100.

  6. Next to Triggering action, select one of the following:

  7. Click Save.

Step 5: Configuring Email Reputation

Email reputation verifies IP addresses of incoming email messages using the Trend Micro Email Reputation database.

  1. Choose IP Filtering > Email Reputation from the menu. The Email Reputation screen appears.

  2. Select the Enable Email Reputation check box.

  3. Click a radio button next to one of the following, depending on your level of service, and configure the settings:

  4. Standard:

    Advanced:

  5. Click Save.

See also:

Configuring IP Filtering

Displaying Suspicious IP Addresses and Domains