Login to participate
Security IdeasRSS
idea RSS
1 - 20 of 76
2
Suggested October 27, 2009 2:17PM by Kayuu23
SBG GUI interface should report correct version information when internet access unavailable. Currently, when you access the "Software and Services"  tab of the Status > Hosts section of the GUI, the page will time out, and upon refresh not display the Control Center or Scanner version. This data is local and should be available. A shorter timeout on the internet access would also be advisable.
No comments yet.
1
Suggested October 12, 2009 10:54AM by Kayuu23
Currently the only disposition available for messages identified by the language filters is to delete the message. It would be nice to allow additional dispositions, such as being able to quarantine the message.
No comments yet.
0 votes
Suggested November 19, 2009 1:00PM by jkoffa
In Symantec Brightmail Message Filter 6.1.1 there is no way to determine the exact Antivirus definitions including revision number. This information is helping in troubleshooting a virus situation where you want to verify the Rapid release and Daily Certified versions running on brightmail Brightmail.
No comments yet.
0 votes
Suggested November 17, 2009 4:39PM by brhode
Many spam messages contain a characteristic in which the sender and the recipient are the same.  Currently there is no way to configure a compliance policy to react to this.  It would be nice to have the ability to toggle an advanced setting in which sender=recipient.
No comments yet.
1
Suggested November 13, 2009 3:57AM by mon_raralio
I'd like to have a feature for Symantec Brightmail Gateway to replicate between Control Centers. At least sychronize the alerts and notifications and/or the configuration, so it can be managed by either CCs or at least on primary CC can control a secondary one. This is useful for disaster recovery should one machine or network go down. For disaster recovery stuff.
No comments yet.
1
Suggested October 27, 2009 8:45AM by toby
Hello together, in the Idea "https://www-secure.symantec.com/connect/idea/brightmail-gateway-and-traffic-shaper" I mentioned that I would like to secure the appliance by itself again and not only to count on the firewall configuration. So the statement of Symantec was more to use other mechanisms as the Symantecs. So I also do not trust the Traffic Shaper generated SSL certificate. I would like to have the possibility to use my own certificates I requested from a certified ...
1 Comments (last comment 3 weeks 5 days ago)
1
Suggested October 21, 2009 8:51AM by phhowe17
I have policy groups with large member counts (LDAP isn't an option).  As a result, any change in the GUI takes 2-3 minutes to replicate to my scanners (CC + 2 scanners). CC should only replicate changed content e.g. if I add a Good Sender, only that data should replicate (actually just the delta, think rsync),  if I create a policy, just replicate the policy.
No comments yet.
2
Suggested October 20, 2009 4:25PM by phhowe17
All logs should use a consistent time format, and one that is easly imported into other tools that recognizes date/time fields (MS Excel/Access in my case).  It's a really pain when reviewing message logs to convert the  "Tuesday, ...." format.  And system logs with m/d/y and unix epoc time, etc should all be normalized to one format.  The format should be selectable to match local date time formats.
No comments yet.
2
Suggested October 19, 2009 11:17PM by Alan Burton-Woods
Currently it is not possible to generate reports on TLS usage. Idea: Implement reporting for TLS encryption usage Case: Any enterprise that implements controls on email encryption needs to be able to verify and report on the effectiveness of these controls. Encryption is something that auditors seem to always be interested in, and there is a need to be able to prove that policy is being enforced correctly. Brightmail cannot currently do this.
1 Comments (last comment 4 weeks 5 days ago)
1
Suggested October 19, 2009 11:57AM by JMoser
It would be great if whitelisted IPs and domains would bypass Language filtering. i love the language filtering feature, but since it is all on or all off, if you run into false positives you don't have a lot of options. It would also be beneficial if the detected language was logged somewhere for troubleshooting purposes.
No comments yet.
0 votes
Suggested October 19, 2009 11:47AM by phhowe17
The Certificate Signing Request (CSR) generated from the Brightmail application is signed with the md5RSA signing algorithm. We prefer sha1RSA. Symantec should not be using md5RSA as it is weak and exploits for those weaknesses are in the wild. How do we implement Sha1RSA on the appliances?
No comments yet.
4
Suggested October 19, 2009 4:33AM by rtatz
Many domains like yahoo and wowway rate limit their inbound traffic when the receive large amounts of mail from a sender.  This becomes a problem when sending legitimate messages that need to be received in a timely manor.  It would be nice if the SBG could be configured to throttle messages to these domains so  one is not blacklisted or marked as SPAM.
2 Comments (last comment 5 weeks 16 hours ago)
1
Suggested October 16, 2009 4:17AM by toby
Hello, in the SBG Control Center you can define several reports for each module like SPAM, Messages, Connection and Viruses. Curently if you would like one "beautiful" management report you have to search for information and create your own report. Furthermore if you have that reports scheduled to send you the information it is complex to handle these mails. So my question is, whether it is possible to have a report template where you can define necessary information of all modules ...
No comments yet.
Status:
In Review
1
Suggested October 12, 2009 3:26PM by phhowe17
It would be nice to have a queue status by recipient domain in the GUI.  Is there a CLI way of getting this info? Option to filter using domain/subdomain Option to select which scanners to include: [x] all [x] scaner 1   [ ] scanner 2  [x] scanner 3 Option to export Like the Status / Hosts / Queues, but by domain instead of scanner. e.g. recipient domain        inbound   outbound   ...
No comments yet.
2
Suggested October 12, 2009 5:28AM by toby
Hello, in a Brightmail infrastructure with requirements of special routes and dedicated policies for a domain, based on the location of the Brightmail Gateway, it would be helpful to have the possibility to bind a configuration dedicated to one or more hosts, but not to all. Is there something planned that, currently from that point I must create different control centers with different policies to enable that feature. Considering the environment (buzzword green-it) this cost a lot of ...
No comments yet.
2
Suggested October 9, 2009 7:39AM by toby
Hello, using the Brightmail Gateway and Traffic Shaper in DMZ with public IPs is in the current implementation of Symantec critical. If you consider that the webserver running on your appliances also on the external interface available is. At the moment Symantec has only a workaround for the command line interface based on SSH Keys. Maybe Symantec will implement a feature which allows to assign the webserver to a interface/IP. This would be very helpful and more secure than your current ...
2 Comments (last comment 6 weeks 1 day ago)
1
Suggested October 7, 2009 11:28PM by toby
Hello, after some test we discovered that an annotation in brightmail gateway is only a textstring without any formatting. So you must use the HTML annotation, but only in following cases: If these MIME parts are found... And annotations have been specified… Then... Text only Plain text only Plain-text annotation is added to the message Text only Plain text and HTML Plain-text annotation is added to the message; HTML annotation is not used Text and ...
No comments yet.
2
Suggested October 6, 2009 2:57AM by toby
Hello, using TLS encryption outbound you have several settings you can configure to send a mail to a destination using TLS. - Attempt TLS encryption - Require TLS encryption and don't verify certificate - Require TLS encryption and verify certificate When we speak about inbound it is not possible to enforce the TLS due to the constrained interface and options of Symantec. So you can only choose "Accept certificate", but in that case if the sender will not use the certificate ...
No comments yet.
1
Suggested October 2, 2009 6:03AM by phhowe17
When searching for mail from an particular sender, and when the logs don't show anything for the sender domain, it would be helpful to be able to search by connection IP with a CIDR formated IP address range. This would be used when the appliance is rejecting, predata, based on reputation.
No comments yet.
3
Suggested September 29, 2009 4:38AM by rtatz
Sites like Yahoo continiueouly rate limit e-mail traffic.  They do not support SPF, but rather Domain Keys.  It would benefficial if Symantec could add Domain Key support to the Brightmail Gateway.
1 Comments (last comment 7 weeks 6 days ago)
Status:
In Development
1 - 20 of 76
Show Listings per page