Configuring Symantec Brightmail Gateway 8360

Paul Mapacpac's picture

Hi, really new to SBG, if anyone could help, would like to ask the ff questions;

1. for the Local and Non-Local how is it routed? How would SBG differentiate?

2. How to add a host file on the appliance?

3. Created a PCC rule for credit card, and it doesnt work, but when I ran a report there are some detections but the controlled email we sent was not filtered or caught.. How do I view actual Compliance detections per message? like a risk list view?

Thank you...

KevK76's picture

Questions

1. Not really sure what you mean here, when you configure local domains you define where to route messages for these domains to, if you don't actually define where to route these messages to they get routed to the Inbound Local Mail Delivery host(s) you've defined during the site setup.  Outbound messages get routed to the 'Outbound Non-local mail delivery' you defined during site setup, this is normally set to use mx if the SBG will send messages directly to the internet.  If you want to send outbound messages to particular domains through a different route other than mx you can define these as Delivery domains on the Protocols -> Domains page and specify the route you want these messages to take(don't check the box to make it a local domain).  The SMTP Settings defined during site setup can be modified by editing a Scanner and clicking the SMTP tab.

2. There isn't really a way to do this, can you let us know why you would need to do this?

3. What do the message audit logs report, they should really tell you what policies have fired?  If you are using the premium credict card pattern my experience has always been that you actually need to use a valid credit card number for the policy to fire. 

 

Paul Mapacpac's picture

Re

Thanks for the reply Kev,

3. I have generated a report and 15 violations were in the summary, but I want to see is the actual messages, is this in the message auditing logs? How can I view all of the violations? It seems on the message auditing menu, you have to be specific on the filter? Can I use wildcards?

Paul Mapacpac's picture

Re

Btw sir, how can I see the MAC Address on the GUI?

Gizzle's picture

 hi paul,

 hi paul,
first of all which OS are you using?
bt i had posted for both XP and Vista.....
I had someone stop by the site recently looking for information on how to find their network card's MAC address, also known as a physical or hardware address. I realized that it's it's easiest to get the MAC address via the command line. In Windows, the command is ipconfig /all, while Mac OS X users would type ifconfig into the Terminal application.

for windows XP
Finding your MAC address in Windows XP is easy with the command prompt. Click Start->Run and then type cmd and press enter. When you see the CMD window, type ipconfig /all. You may see a few Physical address entries here, but the one you're looking for will include an IP address, while the other ones probably won't.

imagebrowser image

To find your MAC address in the Windows XP GUI, open Control Panel by clicking Start->Control Panel
Double-click the Network Connections icon, then right-click your network connection and click Status. Your network connection is usually named Local Area Connection if you're connected to a wired network.
Click the Support tab and then the Details... button and a dialog will show your network connection's MAC address, along with other relevant connection information.

for windows vista
Like Windows XP, Vista makes it easy to get your MAC address via the command line. Click Start, type cmd into the Start search box and then hit the Enter key. Type ipconfig /all in the CMD window and look for the entry that includes an IP address. The physical address is your MAC address.
In the Vista GUI, you'll need to click the network icon in your Windows system tray, also known as the notification area. On a wired network, the icon looks like two monitors, or two monitors with a little globe. Click the entry in the pop-up menu, which will be similar to the one shown below.
You'll be presented with a dialog similar to the one below, and you'll need to click the View Status link for your local area connection if you're on a wired network.
In the Local Area Connection Status window, click the Details... button and look for the Physical Address entry in the Network Connection Details window.

hope its help......

if u want to know the same for mac.....please tell okk......

Paul Mapacpac's picture

Re

Hi, Gizzle I was referring on SBG, the mac address of SBG. If it's possible to see the mac addresss of the eth's via GUI, i know it can be seen via cli.

KevK76's picture

Mac Address

Hi Paul,

Did some hunting today, but really don't think the MAC address is available anywhere from the Control Center so looks like you need to get it from the cli.

Kevin

Paul Mapacpac's picture

Re

Yah, i have been looking for it on the GUI for the past 3 days really cant see it. Thanks,

Paul Mapacpac's picture

Re

Another question, How can I view a list of all the all of the messages on the Message Auditing feature.?

2. Based from the Reports we have compliance violations, how come we don't receive the notifications? are these sent back to the users?

KevK76's picture

Questions

Hi Paul,

Can you please create new threads for new questions with a related subject, if you don't this doesn't really help anyone else on the forum.

1. The message Audit Log Feature is a troubleshooting tool for finding out what happened to specific messages and not really for listing what happened to all messages.  You should make the queies as detailed as possible by providing both the madatory and optional filters.  Saying that, why don't you enter just your local domain name as the sender or recipient mandatory filter and that should give you a pretty good idea on both incoming and outgoing messages. If you are looking to find ou what messages got specific verdicts using the verdict optional filter can be very useful.

2. Have you actually created a notification and set the complianace policies to send notifications to either the sender, recipient or an admin?  If you want to see copies of the message you may also want to use the create an incident message, or even look at creating an inicident and using the hold for review functionality if you don't want the message to be sent unless it's approved.

Cheers,

Kevin

Paul Mapacpac's picture

Re

Hi sorry Kev,

1. Thanks, I just need clarification for this.

2. I manage to test the notification, I need to check the Other, if I want them to be sent to the administrators.