[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference noted::seal

Title:SEAL
Moderator:GALVIA::SMITH
Created:Mon Mar 21 1994
Last Modified:Fri Jun 06 1997
Last Successful Update:Fri Jun 06 1997
Number of topics:1989
Total number of notes:8209

1725.0. "mimesweep" by IJSAPL::VANHULST () Tue Jan 21 1997 10:07

T.RTitleUserPersonal
Name
DateLines
1725.1adding MimesweeperGALVIA::KEATINGTue Jan 21 1997 12:2849
1725.2QUICHE::PITTAlph a ha is better than no VAX!Wed Jan 22 1997 05:5767
1725.3web scanEEMELI::EINAMOWed Jan 22 1997 06:565
1725.4restrict mail through gate/screend ?TLAV02::RUDIMon Jan 27 1997 22:5211
    RE: .2 the part of "mimesweep as internal mailhub as far as FW
    concerned" and "FW accepting outbound mail from only mimesweep"
    
    I assume that with a gatekeeper -- gate -- mimesweeper setup, you can
    configure screend on gate to allow SMTP traffic only between
    mimesweeper and gatekeeper. No idea though how to restrict traffic from
    any mail client/server to mimesweeper or any mailserver behind it.
    Please correct me whem I'm wrong.
    
    rudi
    
1725.5QUICHE::PITTAlph a ha is better than no VAX!Tue Jan 28 1997 04:326
Re .4: You're right.  If you have a gate machine, then you can use that to
restrict access to the smtp port on the firewall to be only from the mimesweeper
box.  I don't think you have to do anything else - inbound all mail will be
given by the firewall to the designated mailhub anyway.

T
1725.6mimesweeper implementation plan based on NT ?IJSAPL::VANHULSTTue Jan 28 1997 08:2035
    
    proposal of mimesweeper structure:
    
    Internet
    	!
    router		NTsystem + Mimesweep
    	!		   !
    --------red net -----------
        !
    NT firewall
    	!
    router
    	!
    --------- blue net --------
    	
    All incoming smtp (mail) messages will be forwarded to the NT-server
    running Mimesweeper either by the firewall or the external router? .
    After screening all smtp messages by mimesweeper, the smtp message
    without any suspicious contents will be forwarded to the firewall .... 
    the firewall will accept only those smtp messages send by the NT-sweep
    system (IP adres check and spoofing protected by the router)
    AV firewall will forwarded those controlled messages to the blue net 
    
    Ingredients:
    NT-system
    Mimesweeper
    Implementation effort (couple of days)
    
    So the question will this work with our and AV NT-firewall has the flexibility to 
    do this kind of smtp routing ?
    
    regards, 
    
    Henk
     
1725.7QUICHE::PITTAlph a ha is better than no VAX!Tue Jan 28 1997 09:597
The only installation I've done that had mimesweeper ran it on the internal
network.  That way it was protected by the firewall.  I feel this is a better
configuration that the one you've drawn up.  After all, you can't actually stop
anyone sending their mail direct to your firewall, even if the MX records only
point to the Mimesweeper box.

T
1725.8put Mimesweeper behind AT LEAST a packet filterANNECY::CHATEL_MThu Jan 30 1997 05:496
    Besides, the NT mimesweeper is probably a "standard" NT machine with
    the "standard" security holes...
    
       You don't want that facing the Net directly, I'd say...
    
    Marc Chatel @ AEO
1725.9NCMAIL::SMITHBThu Jan 30 1997 12:124
Would using the "% hack" be a way of making the mimesweeper box forward 
mail to gatekeeper without scanning it?

Brad.
1725.10Router ACL's ?UTRUST::HEEMSKERKFri Jan 31 1997 09:3617
    Can't we do anything with ACL's on the routers? (permit only traffic
    with dest port 25 to the NT/MIMESweeper machine?
    Deny all the other destinations with port 25. Just a thought...
    
    Tony:
    An advantage of placing MIMESweeper outside of your LAN on the rednet,
    is of course that only *trusted* mail enters your LAN. Local mail
    wouldn't have to be tempered with. (i.e. scanned for certain words
    (go wash your mouth!) Also mail sent to the internet is being scanned
    for virusses/bad language etc. etc)
    
    MarcoMarco
    
    
    Just a thought...
    
    Marco
1725.11internal mail ??SNOFS1::NANCARROWWed Feb 05 1997 01:5414
    I do not understand why mimesweeper would scan internal mail if it
    is not the mail hub itself you would have to re-configure mail to go
    through it rather than it scanning all internal mail.
    advantages of it being on the internal network should include
    management supevision without openning a hole in the firewall and
    ease of use.
    My one concern would be the fact that the box would be receiving
    the mail alarms from the firewall and would have to forward them on to
    the mail hub and it would be a long path to it's destination. Would
    that cause a problem, the firewall tends to crash if the alarm queue
    length gets to long in mail or conversely can the firewall be told to
    send it's alarm mail to a node direct instead of the mail hub ?
    
    					Mike N.