本文档介绍如何创建邮件过滤器,将SMTP身份验证的用户名与信头From:地址 .
思科建议您了解适用于邮件版本15.0及更高版本的Cisco AsyncOS。
SMTP身份验证功能允许客户对其邮件客户端使用SMTP身份验证,以通过思科邮件安全设备(ESA)连接和发送邮件。 由于此功能允许经过身份验证的会话中继出站邮件,因此客户端可以假冒信头From:地址 .为帮助防止欺骗,Cisco AsyncOS for Email 6.5版及更高版本包含邮件过滤条件,将经过身份验证的SMTP用户名与信头From:地址并将用户名记录在X报头中。
邮件过滤器条件允许管理员编写过滤器(例如,下一节中的规则),比较在SMTP身份验证会话期间出站中继的邮件。如果SMTP凭证受损,发送客户端通常会生成多个信头From:地址。此条件允许仅在经过身份验证的用户名与信头From:地址 ;否则,该邮件将被视为伪装信头From:并应用配置的邮件过滤器操作。邮件过滤器操作可以是任何最终操作;示例规则使用隔离操作。过滤条件的语法如下:
smtp-auth-id-matches("<target>" [, "<sieve-char>"])
可选的sieve-char参数指定用于忽略比较地址中该字符之后的部分的分隔符字符(例如+)。如表所示,这通常用于加编址。
过滤器允许与以下目标之一进行比较:
| SMTP身份验证ID | 筛过炭 | 比较地址 | 匹配? |
|---|---|---|---|
| 某些用户 | otheruser@example.com | 无 | |
| 某些用户 | someuser@example.com | Yes | |
| 某些用户 | someuser@face.localhost | Yes | |
| SomeUser | someuser@example.com | Yes | |
| 某些用户 | someuser+folder@example.com | 无 | |
| 某些用户 | + | someuser+folder@example.com | Yes |
| someUser@example.com | someuser@forged.com | 无 | |
| someUser@example.com | someuser@example.com | Yes | |
| someUser@example.com | someuser@example.com | Yes |
此变量替换$SMTPAuthID允许将经过身份验证的用户名包括在经过身份验证的SMTP会话期间中继的消息的消息标头中。
Msg_Authentication: if (smtp-auth-id-matches("*Any"))
{
# Always include the original authentication credentials in a
# special header.
insert-header("X-SMTPAUTH", "$SMTPAuthID");
if (smtp-auth-id-matches("*FromAddress", "+") and
smtp-auth-id-matches("*EnvelopeFrom", "+"))
{
# Username matches. Verify the domain.
if (header('from') != "(?i)@example\.com" or mail-from != "(?i)@example\.com")
{
# User has specified a domain which cannot be authenticated.
quarantine("forged");
}
}
else
{
# User claims to be a completely different user.
quarantine("forged");
}
}
| 版本 | 发布日期 | 备注 |
|---|---|---|
1.0 |
11-Jun-2014
|
初始版本 |