Data Loss Prevention

 View Only
  • 1.  DLP - MailPrevent listening on multiple ports ?

    Posted May 28, 2013 01:13 PM

    Hello

    I have the current situation right now:

    I have implemented the DLP in production in a customer for analyzing all the mail traffic, and it's working fine. But now, the customer has implemented a Fax Server in the company. Basicly consists in:

    -The user creates a fax in Outlook by specifying in the "To:" field something like [fax:0123456]

    -The Exchange has an special send connector that knows howto send all these kinds of fax encapsulated on mails to a gateway fax server

     

    So, now i need to analyze all this fax trafic with DLP, but i need that the DLP could be capable of knowing wich traffic is mail traffic so it could send to the proper smarthosts (antispam) and at the same time be capable of noticing wich traffic is fax traffic and send it to the gateway Fax Server so it could know what to do with it. Am i explaning?

     

    AS A POSSIBLE WORKAROUND I'M THINKING: I know that in the Exchange Servers I could configure the involved send connectors so it could send the mail traffic to the DLP on some random port (and of course the MailPrevent would need to be listening on this port) and the fax traffic to the DLP on other port (In this case, the MailPrevent would need to listen on another port, analyze the email, and after processing it send it to another smarthosts)

    Basicly, I think I need to set two Forward modes into the same DLP Mail Prevent Server, so it would forward different traffics to differents smarthosts. Is this possible. How can I achieve that?

    Please let me know if it's not clear so i could try to provide a better description

    Thks all for your help!



  • 2.  RE: DLP - MailPrevent listening on multiple ports ?
    Best Answer

    Posted Jun 11, 2013 12:05 PM

    Apereira,

    SMTP Prevent functions as an SMTP proxy (not an MTA), so it only recieives on one port and forwards on to a set location (or back to the sender in Reflect Mode). Because it's a proxy it is not allowed to route to different locations based on the message content.

    What you need to do is setup another SMTP Prevent box to handle the eFax traffic. Have Exchange route the eFax traffic to the new Prevent server and then have that Prevent server setup to forward mail to the appropriate smarthost.

    Let me know if you have any other questions!

    Tim



  • 3.  RE: DLP - MailPrevent listening on multiple ports ?

    Posted Jun 20, 2013 09:50 AM

    Hi Tim,

     

    Yeah, that's what i figure out. I just wanted to have someone else's perspective in case I missed something

    Thks for the return

     



  • 4.  RE: DLP - MailPrevent listening on multiple ports ?

    Posted Jun 20, 2013 10:02 AM

    Depending on which fax software you use it may never hit the NP for rmail server, look and see if you a modem installed in the back of your server, you may be sending and receiving faxes that way. IF that is the case you  may need endpoint agents on the clients.