Views:
All settings in IMSS or IMSVA will be migrated to Cloud Email Gateway Protection completely or partially except those listed in Data That Will Not Be Migrated. Among the settings that are partially migrated, some are modified to adapt to Cloud Email Gateway Protection due to the feature differences between IMSS or IMSVA and Cloud Email Gateway Protection. Therefore, you need to confirm or fix these settings according to the on-screen instructions after migration.
The following table lists some examples of the settings that will be partially migrated and describes the feature differences.
Note
Note
For details about all the settings that are completely or partially migrated, see the data migration report downloaded from the Cloud Email Gateway Protection administrator console when the migration completes.
Navigation in IMSS or IMSVA
Source Settings
Navigation in Cloud Email Gateway Protection
Destination Settings
Feature Differences
PolicyPolicy List
The following settings on the Step 1: Select Recipients and Senders screen:
  • Sender
  • Recipient
  • Sender to recipient exception
The following submenus under the Inbound Protection and Outbound Protection menus:
  • Virus Scan
  • Spam Filtering
  • Content Filtering
  • Data Loss PreventionData Loss Prevention (DLP) Policy
The following settings in the Senders section of the Recipients and Senders tab:
  • Sender
  • Recipient
  • Sender to recipient exception
LDAP users in IMSS or MISVA are migrated as static email addresses in Cloud Email Gateway Protection.
Condition match settings on the Step 2: Select Scanning Conditions screen
  • Inbound ProtectionContent Filtering
  • Outbound ProtectionContent Filtering
Condition match settings in the Advanced section of the Scanning Criteria tab
Only content filtering supports all condition matched (AND).
True file type settings in the Attachment section of the Step 2: Select Scanning Conditions screen
  • Inbound ProtectionContent Filtering
  • Outbound ProtectionContent Filtering
True file type settings in the Advanced section of the Scanning Criteria tab
Cloud Email Gateway Protection does not support MSI, PNG, 7-Zip, or Microsoft Windows shortcuts.
Global DKIM Enforcement rule
Inbound ProtectionDomain-based AuthenticationDomainKeys Identified Mail (DKIM) Verification
Settings in the Default (for unspecified domains) policy (including the action and Enforced Peers)
Cloud Email Gateway Protection uses both the header sender address and envelope sender address instead of only the header sender address for matching the list of enforced peers.
PolicyApproved List
The settings of the following approved lists:
  • DKIM approved list
  • Web reputation approved list
  • URL keyword list
  • Inbound ProtectionDomain-based AuthenticationDomainKeys Identified Mail (DKIM) Verification
  • AdministrationPolicy ObjectsWeb Reputation Approved List
  • AdministrationPolicy ObjectsURL Keyword Exception List
The settings of the following approved lists:
  • DKIM approved list (Ignored Peers section in the Default (for unspecified domains) policy)
  • Web reputation approved list
  • URL keyword exception list
Cloud Email Gateway Protection uses the envelope sender address instead of the header sender address for matching the list of ignored peers.
PolicyPolicy ObjectsAddress Groups
Name and address settings of an address group
AdministrationPolicy ObjectsAddress Groups
Name and address settings of an address group
Cloud Email Gateway Protection supports wildcard domains (for example, *@*.example.com) in hybrid address groups, and does not support wildcard domains in internal address groups.
If an address group is used as senders (or sender exceptions) in outbound policies or recipients (or recipient exceptions) in inbound policies and the group contains email addresses from unmanaged domains, Cloud Email Gateway Protection will create a copy of the address group, delete those email addresses from the copy, and suffix the copy name with " - internal".
PolicyPolicy ObjectsKeywords & Expressions
Match settings of a keyword or expression
AdministrationPolicy ObjectsKeywords and Expressions
Match settings of a keyword or expression
None
PolicyPolicy ObjectsPolicy Notification
Variables list in the settings of a policy notification
AdministrationPolicy ObjectsNotification
Variables list in the settings of a policy notification
Cloud Email Gateway Protection does not support the following variables:
  • %RULETYPE%
  • %ENTITY%
  • %QUARANTINE_PATH%
  • %QUARANTINE_AREA%
  • %PROTOCOL%
  • %HOSTNAME%
  • %MAILCHARSET%
  • %SUSPICIOUS_URL%
Sender FilteringApproved List
The following settings of an approved list:
  • IP addresses
  • Groups of computers
Note
Note
Cloud Email Gateway Protection migrates IP addresses and groups of computers from IMSVA only if the Email Reputation and IP Profiler check box to the right of Apply to is selected. This restriction does not apply to IMSS.
Inbound ProtectionConnection FilteringIP ReputationApproved IP Addresses
IP address settings in the IP addresses section
Cloud Email Gateway Protection does not support the following settings:
  • IP addresses resolved from domains
  • Private IP addresses
  • IP addresses in disabled approved lists
Sender FilteringBlocked List
The following settings of a blocked list:
  • IP addresses
  • Groups of computers
Note
Note
Cloud Email Gateway Protection migrates only IP addresses and groups of computers whose Action is Block Permanently.
Inbound ProtectionConnection FilteringIP ReputationBlocked IP Addresses
IP address settings in the IP addresses section
Cloud Email Gateway Protection does not support the following settings:
  • IP addresses resolved from domains
  • Private IP addresses
  • IP addresses in disabled blocked lists
Sender FilteringDMARC
DMARC settings
Note
Note
DMARC settings are available only in IMSVA.
Inbound ProtectionDomain-based AuthenticationDomain-based Message Authentication, Reporting and Conformance (DMARC)
DMARC settings
Cloud Email Gateway Protection uses both the header sender address and envelope sender address instead of only the header sender address for matching the list of enforced peers.
AdministrationIMSVA ConfigurationDKIM Signature
Advanced settings of DKIM signatures
Note
Note
DKIM signatures are available only in IMSVA.
Outbound ProtectionDomain-based AuthenticationDomainKeys Identified Mail (DKIM) Signing
Advanced settings of DKIM signatures
Cloud Email Gateway Protection does not support exempt domains.