JuniperForum.com
July 29, 2010, 07:52:14 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: If you have an interesting idea for an article or knowledgebase entry, please submit it!
 
  Home Help Login Register  
* *
Pages: [1]
  Print  
Author Topic: Spam Filter  (Read 2864 times)
steve.whitelock
Guest
« on: November 29, 2007, 08:35:41 AM »

I personally think that the spam filtering options on the juniper firewalls should have the ability to have a black list that searchs subject headings...

e.g. if you put "Viagra" in it would treat all mail through that policy with this subject as spam and drop, mark etc as so...

As it stands the blacklists are only for known email addresses and ip addresses, of course this is ok if all your spam comes from the same place, we all know in the real world this is not the case...

I am a little dissapointed at present with these features on my SSG140
Logged
sfouant
Full Member
***
Posts: 109



View Profile
« Reply #1 on: November 29, 2007, 09:29:09 AM »

I know this isn't exactly what you are getting at... but technically you could do this by enabling DI and configuring a User-Defined Signature to search the 'smtp-header-subject' context within protocol SMTP.  It'd be a real pain to configure blacklists in this way however. Wink
Logged

Stefan Fouant, CISSP
sfouant
Full Member
***
Posts: 109



View Profile
« Reply #2 on: November 29, 2007, 09:43:03 AM »

Unfortunately yes...

set attack cs:spam smtp-header-subject .*viagra severity info
set attack cs:spam smtp-header-subject .*cialis severity info

You could use Regular Expressions to match various patterns however...
Logged

Stefan Fouant, CISSP
sfouant
Full Member
***
Posts: 109



View Profile
« Reply #3 on: November 29, 2007, 09:46:44 AM »

Actually I put the commands incorrect above...

You'll actually need to name each custom signature differently, as in the following:

set attack cs:spam1 smtp-header-subject .*viagra severity info
set attack cs:spam2 smtp-header-subject .*cialis severity info
set attack group spam add spam1
set attack group spam add spam2
Logged

Stefan Fouant, CISSP
sfouant
Full Member
***
Posts: 109



View Profile
« Reply #4 on: November 29, 2007, 09:54:10 AM »

so by doing this it would delete the messages

It depends on the action you've specified for the DI settings in the policy, you can do various things such as close the connection and send a reset, sever the connection without sending a reset, ignore (useful for logging), drop the packet, or take no action at all.  In your case you'll probably want to set it to drop the packet.
Logged

Stefan Fouant, CISSP
gr33ndata
Sr. Member
****
Posts: 366


View Profile WWW
« Reply #5 on: April 22, 2008, 03:21:49 AM »

I think Juniper have to enhance their AntiSpam thing, as the use of IP-Addresses Blacklist (RBL's) only is useless. They shall be able to do some Bayesian Analysis of the mails in order to Allow or Block them.

The main problem with RBL's is that it cannot stop the outgoing spam, which is really important for ISP's, as all the mails will be coming from the same address (their servers IP address).
Logged

Gr33nData, or you may call me NetScream
JNCIS-FWV, and JNCIA-IDP
http://gr33ndata.blogspot.com/
oldo
Sr. Member
****
Posts: 497


View Profile
« Reply #6 on: October 12, 2008, 11:52:39 PM »

Well, I wouldn't mind if they scrapped the Anti-Spam feature all together. We have only sold one single license, and after evaluating it myself I told our sales force to not even mention it to customers. They really need to come up with something that actually filters out spam to greater extent, and with accuracy.  Why buy a license for Anti-spam if you need a second device/software to do the job properly?
Logged

JNCIA-FW, JNCIA-AC, JNCIS-SSL, Ironport ICSP, xSeries Specialist,
sebastan_bach
Sr. Member
****
Posts: 349


View Profile
« Reply #7 on: October 13, 2008, 03:30:00 AM »

yeah even think juniper should really focus on getting the spam features . if they don;t have it in built they could just integrate it anti-spam vendors so we can integrate juniper firewalls with anti-spam vendors of our choice.

and they  should add support for pop3 currently i guess it only supports filtering using smtp .

regards

sebastan
Logged
Pages: [1]
  Print  
 
Jump to:  

Navigation

Donate

Please consider donating if we've saved you time or money. It helps pay for the bandwidth, equipment, and hosting charges to keep this site running

Tools

Submit Article/KB - Do not submit questions here.

Recent

Stats

Members
Stats
  • Total Posts: 39593
  • Total Topics: 10459
  • Online Today: 72
  • Online Ever: 393
  • (August 06, 2008, 07:40:57 AM)
Users Online
Users: 1
Guests: 28
Total: 29
TinyPortal v1.0 beta 4 © Bloc
Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!

Sponsored in part by CollarWise

Page created in 0.213 seconds with 37 queries.