Integrate ScanMail with
Trend Vision One to forward detection logs to Trend Vision One. You can integrate
with Trend Vision One directly, through a Service Gateway, or through a proxy
server.
ImportantBefore you can configure integration settings, apply the latest hotfix or
patch.
|
Procedure
- Generate an enrollment token in Trend Vision One.
- On the Trend Vision One console, go to or .
- Click Add Existing Product or Connect.
- In the Instance type or Product field, select ScanMail for Microsoft Exchange.
- Click the link to generate an enrollment token.
- Copy the enrollment token for use on the ScanMail product console.
- Click Save.
- On the ScanMail product console, go to .
- In the Connection Settings section, next to
Trend Vision One token, paste the enrollment token
you obtained in this step.
Note
If you only specify the token without configuring the other connection settings, ScanMail will directly connect to Trend Vision One. - If you want to connect to Trend Vision One through a Service Gateway, complete
the following procedure.
- On the Trend Vision One console, go to .
- If you do not have an existing Service Gateway deployed, install a
Service Gateway.For detailed instructions, see Deployment Guides.
- Click the Service Gateway name.
- Click Manage Services.
- Click the install icon to install the Forward Proxy
Service, and then enable the service.The Forward Proxy Service comes with a default port for ScanMail. If you want to use a custom port, change the port in the Forward Proxy Service configuration screen of the Trend Vision One console. ScanMail automatically applies the custom port when integrating with Trend Vision One.
- Record the Service Gateway IP address for use on the ScanMail product console.
- On the ScanMail product console, go to .
- Select Enable Service Gateway connection.
- Specify the Service Gateway IP address you obtained in step 6.
- If you want to connect to Trend Vision One through a proxy server, complete the
following procedure.
Note
You can only choose to connect to Trend Vision One through either a Service Gateway or a proxy server.- Select Use a proxy server to connect to Trend Vision One.
- Specify the host name or IP address of the proxy server and its port number.
- If your proxy server requires authentication, specify the user name and password used for authentication.
- Select Forward detection logs to Trend Vision One.
- Under Suspicious Object List Synchronization, configure the following:
- Select Enable Suspicious Object List, if you want ScanMail to leverage the Suspicious Object Lists from Trend Vision One. ScanMail synchronizes the consolidated Suspicious Object Lists (including the Virtual Analyzer
and User-defined objects) to apply to the specified scan filters.
Important
You can synchronize and apply Suspicious Object Lists from only one of the sources: Apex Central, Deep Discovery Director, or Trend Vision One. Determine the source that you want to use and enable suspicious object list synchronization in the corresponding configuration screen. - Select the scan filters that you want the Suspicious Object Lists to apply to. Available filters are Security Risk Scan and Web Reputation.
- Select Enable suspicious objects detection notification to receive notifications about suspicious objects detections. The details of Security Risk Scan detection and Web Reputation detection follow their notification settings.
-
The scanning and decision processes for suspicious objects in the Security Risk Scan filter follows the following priority:User-defined suspicious objects > Pattern-based local scan > Virtual Analyzer reported suspicious objects
-
The scanning and decision processes for suspicious objects in the Web Reputation filter follows the following priority:User-defined suspicious objects > Virtual Analyzer reported suspicious objects > Web Reputation Services scan
The action mapping in ScanMail for the Trend Vision One settings is defined in the following table.Action mapping table for suspicious objects
Scan FilterTrend Vision One Action SettingScanMail ActionSecurity Risk ScanLogPassBlockQuarantine entire message (real-time scan)Quarantine message part (manual/schedule scan)Web ReputationLogPassBlockQuarantine entire message - Select Enable Suspicious Object List, if you want ScanMail to leverage the Suspicious Object Lists from Trend Vision One. ScanMail synchronizes the consolidated Suspicious Object Lists (including the Virtual Analyzer
and User-defined objects) to apply to the specified scan filters.
- Click Register.