06-14-2011 07:27 AM
I have had some reports recently from different clients of mine that they have seen an increase in the number of messages that are getting through the Ironport filter. I have been researching the issue to see if we have a misconfiguration somewhere that is allowing the increase to happen. Granted they still have about 90% of their spam blocked but some messages that are getting through are causing a tiny bit of concern for me.
What I have checked:
Any ideas of other things to try would be great. I have considered increasing the max message size to 512MB as these devices are not really using too much of their memory/processor power. And I have looked over the Answer ID article 493 "IronPort Anti-Spam Efficacy Checklist". Has anyone else noticed an uptick of spam that is trickling trough? As I mentioned it is not an obscene amount, but it is enough for clients to have taken notice.
All of the devices we are using are Ironport c150s
And for good measure here's an example of one that has snuck through:
Sending mail server: mta-inap6.bluestatedigital.com [69.25.74.172]
Message Header:
Received: from OutsideClientMX (x.x.x.x) by Ironport_c150
(x.x.x.x) with Microsoft SMTP Server id 8.1.436.0; Tue, 24 May 2011 11:02:21 -0500
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AhEMAPPU201FGUqseWdsb2JhbAAmgkCDdG2edgEBCwsLBwUNBSLJQ4MOIoJrBJAfiFSGLQ
Received: from mta-inap6.bluestatedigital.com ([69.25.74.172]) by
OutsideClientMX with SMTP; 24 May 2011 11:12:29 -0500
Received: by mta-inap6.bluestatedigital.com (Postfix, from userid 506) id
2FBB7744AFE4D; Tue, 24 May 2011 12:02:20 -0400 (EDT)
Received: from maillist-a by bounce.bluestatedigital.com with local
(PHPMailer); Tue, 24 May 2011 16:02:20 +0000
Date: Tue, 24 May 2011 16:02:20 +0000
To: <client-email@something.com>
From: "Robby Mook, DCCC Executive Director" <dccc@dccc.org>
Reply-To: dccc@dccc.org
Subject: Friend, can you call today?
Message-ID: <24499ec8d6b9842f68415aa4cb1a7c93@bounce.bluestatedigital.com>
X-Priority: 3
X-Mailer: PHPMailer [version 1.71-blue_mailer]
X-maillist-id: 719ac85d6f7ef883
X-maillist-guid: AQZVVmpTVw0EUAgAVVNVVgZfCAoH
List-Unsubscribe: <http://www.dccc.org/page/unsubscribe/?email=client-email@something.com>
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="b1_24499ec8d6b9842f68415aa4cb1a7c93"
Return-Path: AQZVVmpTVw0EUAgAVVNVVgZfCAoH@bounce.bluestatedigital.com
Blacklist check of the offending domain is attached.
06-14-2011 10:24 AM
Hi Justin,
Sorry to hear about your frustration with missed spam. It sounds like you have done a bit of diagnosis on your own but I wanted to provide a few extra details here that I think you may find helpful in resolving this issue.
First the basics.
Are your feature keys up to date. If the IPAS feature key expires you will still scan messages for spam but the rule sets will not be up to date. To check the featurekeys you can issue the command featurekey from the CLI.
smurf.run> featurekey
Module Quantity Remaining Expiration Date
Bounce Verification 1 Perpetual N/A
IronPort Email Encryption 0 expired Sat Jun 4 13:55:51
2011
IronPort Anti-Spam 1 8 days Wed Jun 22 19:27:12
2011
Incoming Mail Handling 1 Perpetual N/A
Virus Outbreak Filters 1 16 days Fri Jul 1 14:31:12
2011
Sophos Anti-Virus 1 1 day Thu Jun 16 15:32:28
2011
McAfee 1 30 days Thu Jul 14 17:14:37
2011
Choose the operation you want to perform:
- ACTIVATE - Activate a (pending) key.
- CHECKNOW - Check now for new feature keys.
[]>
The next question is, is IPAS has issues updating? You can check this by issuing the command asstatus or antispamstatus from the CLI. You should see something in the list updated in the last half hour.
murf.run> asstatus
Component Last Update Version
CASE Core Files 23 May 2011 19:39 (GMT) 3.1.0-014
Structural Rules 14 Jun 2011 16:40 (GMT) 3.1.0-014-20110614_051407
Content Rules 14 Jun 2011 17:00 (GMT) 20110614_165620
Content Rules Update 14 Jun 2011 17:10 (GMT) 20110614_170905
CASE Utilities 23 May 2011 19:34 (GMT) 3.1.0-014
Web Reputation DB 13 Jun 2011 20:56 (GMT) 20110613_205102
Web Reputation Rules 14 Jun 2011 17:05 (GMT)
20110613_205102-20110614_170206
Last download attempt made on 14 Jun 2011 17:10 (GMT)
smurf.run>
*Case core files and utilities don't typically get updated as often as the other components.
If the system is not updating you can try to verify connectivity to the update server using telnet by attempting a connection to downloads.ironport.com on port 80
smurf.run> telnet
Please select which interface you want to telnet from.
1. Auto
2. Management (10.92.152.67/24: smurf.run)
[1]>
Enter the remote hostname or IP address.
[]> downloads.ironport.com
Enter the remote port.
[25]> 80
Trying 10.92.144.24...
Connected to downloads.ironport.com.
Escape character is '^]'.
If all of this is ok. we then need to look at why the messages are missed? This data can be found in the mail logs.
If you grep for one of these messages. What do we see for the MID and then if you grep for the ICID what do we see.
The MID will provide us with details such as , was it scanned by CASE? was it too large to be scanned? Was there a scanning error? Was it marked clean?
the ICID will tell us what sendergroup and mail flow policy the messages came in on. This can help us further analyze the message to see if its routed through a sendergroup/mail policy that has spam scanning turned off.
Finally if you provide the full header data we can analyze the messages in more detail to determine what the spam score was and why it was missed.
I am providing detailed instructions on the submissions process below. This would be the next logical step in this process. There is no feedback from this system and if you want specific details you will need to open a ticket with support so we can in turn open a ticket with the COG team (Case Operations Group) who manages the rule sets.
How do I report IronPort Anti-Spam false positives or missed spam?
To send a missed spam or message incorrectly marked as "not-spam" email to IronPort Systems for examination, there are a number of ways to submit messages.
Note: Unless submitted through a plug-in (MS Outlook, not MS Outlook Express), messages forwarded must be RFC-822 compliant attachments. Forwards of previously forwarded messages cannot be processed at this time.
Each message is reviewed by a team of human analysts and used to enhance the accuracy and effectiveness of the product.
Once we receive submissions from a customer or from other sources, these messages are passed through automated classification systems that makes use of our latest rule set. If these messages are tagged by the new rule-set as spam, they are classified as such. Due to a delay in receiving samples and generating rules, many of the missed-spam messages usually have rules published between the time they are received by our customers and reported to us.
There are some messages that are part of new spam trends or new variants that are sufficiently different or new spam strains that are not classified by automated systems. Basically, any messages that are held for classification due to some mitigating factors are held for human review. We attempt to get to these messages within 2-3 hours of them being injested into the corpus.
Note: Although every report sent as an RFC-822 attachment to this address will be reviewed, most submissions will not receive an actual physical reply from IronPort.
Customers using IronPort Anti-Spam or Symantec Brightmail Anti-Spam will want to submit both 'missed spam ' (False Negatives) and messages which are incorrectly classified as SPAM (False Positives). In either case, the submission must be attached to an email as an RFC-822 MIME encoded attachment. This ensures that the submission can be processed quickly and efficiently. The actual steps to follow are different for each mail program (Mail User Agent).
Report undetected spam to: spam@access.ironport.com
Report false-positives to: ham@access.ironport.com
Microsoft Outlook
Lotus Notes
Tested vith Notes versions 6.5.x and 7.0.x
Brightmail Domino Agent -Download from the Cisco IronPort Email Security Page
Outlook Express 6
Entourage (Apple Mac)
Apple Mail.app
Mozilla Thunderbird
Netscape Messenger
I hope this helps. If you need further assistance let us know.
Christopher C Smith
CSE
Cisco IronPort Customer Support
06-15-2011 08:20 AM
Hi Chris
Thanks for the information. I have the Outlook Ironport add-in to report some of the messages that have made it through so I will do that.
I checked the Feature Keys and the CASE updates and everything seems to be running fine and up to date (It attempted to download updates today and the updates were recent).
I need to get you infor from the Mail Logs, let me get a recent spam message. There was a few this morning, but the CASE system was down (we recently lost power and had a reboot at this site but it is all working fine now).
I will get you logging on a message as soon as I get a new one in.
thanks!
06-22-2011 07:32 AM
Chris,
Since you broke down all of the different ways to submit Spam, I though that I would let you know another way for T-Bird users. In looking for something similar to the Outlook plug-in, we found a T-Bird plug-in call mailsentry_ironport_spam_reporter-1.1-tb.xpi. It has a couple of options to either "Report Spam" or "Report Ham". It has worked very well for our users.
If you send me a PM, I will get a copy of it to you. That way, maybe it could become an official plug-in to use for Ironport T-Bird users.
Doug
06-16-2011 02:23 PM
Here's one:
Message Headers:
Received: from smtp2.childdevinc.org (x.x.x.x) by mail.childdevinc.org
(x.x.x.x) with Microsoft SMTP Server id 8.1.436.0; Thu, 16 Jun 2011
06:25:00 -0500
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AkYCAGrn+U0/+800kWdsb2JhbAAyChaCUZwRAYYgeGYUAQEBAQkJDQcSJ7tkjXcBBIMtgnqHIYo8kBY
Received: from smtp52.mail.mylife.com ([63.251.205.52]) by
smtp2.childdevinc.org with ESMTP; 16 Jun 2011 06:35:40 -0500
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; s=ir; d=mail.mylife.com;
h=Date:From:Reply-To:To:Message-ID:Subject:MIME-Version:Content-Type; i=mylife@mail.mylife.com;
bh=LoEu9jyoM6TRYVufjT/LYtf9CxI=;
b=PPVcgiwUsSoqM6dnbmv3nSe6UD0k4Eyas1GipV5Ik7WAlAvQwmv4YZ4vSf5vpyAYupD9aS+Salyf
BNTfcZcKZQ==
DomainKey-Signature: a=rsa-sha1; c=nofws; q=dns; s=ir; d=mail.mylife.com;
b=V3xlBemB9asnG50FKCGiMl5opqxBxCsifIw3ZODPZfDNFuE0QXjz2cuLh1QsxgRcZtGirDBp6x/O
3gSslc34Lg==;
Received: by smtp52.mail.mylife.com (PowerMTA(TM) v3.5r16) id hv7k0m10a1kl for
<user@childdevinc.org>; Thu, 16 Jun 2011 04:24:58 -0700 (envelope-from
Date: Thu, 16 Jun 2011 04:24:57 -0700
From: MyLife Updates <mylife@mail.mylife.com>
Reply-To: noreply-mi@mail.mylife.com
To: User <user@childdevinc.org>
Message-ID: <1900443531.3075371.1308223497778.JavaMail.mailadmin@mail5.reunion.com>
Subject: See our latest results for Christopher Thornton
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_Part_3075369_1703718179.1308223497778"
X-Un: sQU1SkYiLCbLM01w_feIfw**
X-JOB: 3337_06-16-2011
X-reuniontype: 3337
X-au-recp-type: 1
x-virtual-mta: mi
smtp2.childdevinc.org> grep -i "MID 964172" mail_logs
Thu Jun 16 06:35:40 2011 Info: Start MID 964172 ICID 14413195
Thu Jun 16 06:35:40 2011 Info: MID 964172 ICID 14413195 From: <mylife@mail.mylife.com>
Thu Jun 16 06:35:40 2011 Info: MID 964172 ICID 14413195 RID 0 To: <user@childdevinc.org>
Thu Jun 16 06:35:40 2011 Info: MID 964172 Message-ID '<1900443531.3075371.1308223497778.JavaMail.mailadmin@mail5.reunion.com>'
Thu Jun 16 06:35:40 2011 Info: MID 964172 Subject 'See our latest results for Christopher Thornton'
Thu Jun 16 06:35:40 2011 Info: MID 964172 ready 18152 bytes from <mylife@mail.mylife.com>
Thu Jun 16 06:35:40 2011 Info: MID 964172 matched all recipients for per-recipient policy DEFAULT in the inbound table
Thu Jun 16 06:35:41 2011 Info: MID 964172 interim verdict using engine: CASE spam negative
Thu Jun 16 06:35:41 2011 Info: MID 964172 using engine: CASE spam negative
Thu Jun 16 06:35:41 2011 Info: MID 964172 queued for delivery
Thu Jun 16 06:35:41 2011 Info: Delivery start DCID 584828 MID 964172 to RID [0]
Thu Jun 16 06:35:41 2011 Info: Message done DCID 584828 MID 964172 to RID [0]
Thu Jun 16 06:35:41 2011 Info: MID 964172 RID [0] Response '2.6.0 <1900443531.3075371.1308223497778.JavaMail.mailadmin@mail5.reunion.com> Queued mail for delivery
Thu Jun 16 06:35:41 2011 Info: Message finished MID 964172 done
06-21-2011 08:13 AM
Greetings Justin,
From the message headers and log snippet you have sent, it appears that the message has been scanned by IronPort AntiSpam but has not been identified as a spam message. As Chris mentioned above, please send us the original message as an attachment to spam@access.ironport.com and provide us the email address or method you used to submit the message.
You can send multiple messages at once by saving each missed spam in a rfc822 format and then attaching them to an email to spam@access.ironport.com.
Thanks,
Jyothi Gandla
Customer Support Engineer
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide