Email Filter Configuration Example

This section describes an email filter configuration example.

Security Appliance works as the gateway of an enterprise. Ethernet0/0 connects to Internet and belongs to untrust zone; ethernet0/1 connects to the Intranet of R&D department and belongs to trust zone; ethernet0/3 connects to the Intranet of Marketing department and belongs to the trust1 zone.

It is required to forbid the employees to send emails through QQ mailbox, and record the log messages when someone is sending emails through other mailbox.

See the topology below:

This section shows the email filter configurations in details, and for the configurations about interface, zone, and log, see the related chapters.

Configurations

Take the following steps:

  1. On the Navigation pane, click Configure > Content > Email Filter to visit the Email Filter page.
  2. Click New.
  3. In the Email Filter Rule Configuration dialog, type mailfilter into the Name box.
  4. Under Match Conditions, finish the options as below to specify the conditions for the rule.
  5. Under Action, click Specific mail items.
  6. Select the Block/Audit sender check box.
  7. Click the sender link.
  8. In the Sender dialog, type *@qq.com into the Sender box, and then click Add.
  9. Select the Block send check box of *@qq.com.
  10. Click OK to save the settings and return to the Email Filter Configuration dialog.
  11. Select the Record log check box of the Other emails option.
  12. Click OK to save the settings.

After finishing the above configurations, the employees cannot send emails through QQ mailbox, and all the sending actions of other mailboxes will be recorded.