cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1088
Views
0
Helpful
1
Replies

Detecting spam using regular expressions?

AVS_ironport
Level 1
Level 1

Ou users have been geting a lot of russian porn spam last 3 weeks. We decided to make dictionary (regexp) rule to move all the positive detected mails to quarantine. Is it possible to move such messages to M-ceries quarantine, instead "policy" quarantine in C-ceries? And how to make it?

Dual C350, AsyncOS version - 5.5.1

Thank you.

1 Reply 1

Douglas Hardison
Cisco Employee
Cisco Employee

Any filter with an action of 'quarantine' will end up in one of the Policy quarantines.

If your C-Series are configured to send spam quarantined messages to the M-Series, you can configure your filter action to add a header that indicates the message is to be quarantined.

So, for your Russian spam filter:
For the Action, Add header with Header name 'X-Ironport-Quarantine'. The header value can be anything, for instance 'True'

This header directs the IronPort to quarantine the message.