Applies To:Show Versions
- 11.6.5, 11.6.4, 11.6.3, 11.6.2, 11.6.1
Securing SMTP Traffic Using the Default Configuration
Overview: Securing SMTP traffic using system defaults
This implementation describes how to secure SMTP traffic using system defaults. When you create an SMTP security profile, the BIG-IP® Advanced Firewall Manager™ (AFM) provides several security checks for requests sent to a protected SMTP server. When you enable a security check, the system either generates an alarm for, or blocks, any requests that trigger the security check.
You can configure the SMTP security profile to include the following checks:
- Verify SMTP protocol compliance, as defined in RFC 2821.
- Validate incoming mail using several criteria.
- Inspect email and attachments for viruses.
- Apply rate limits to the number of messages.
- Validate DNS SPF records.
- Prevent directory harvesting attacks.
- Disallow or allow some of the SMTP methods, such as VRFY, EXPN, and ETRN, that spam senders typically use to attack mail servers.
- Reject the first message from a sender, because legitimate senders retry sending the message, and spam senders typically do not. This process is known as greylisting. The system does not reject subsequent messages from the same sender to the same recipient.
Creating an SMTP service profile with security enabled
On the Main tab, click
. The SMTP profile list screen opens.
In the Name column, click
The Properties screen for the system-supplied SMTP profile opens.
- Select the Protocol Security check box to enable SMTP security checks.
- Click Update.
Creating an SMTP virtual server with protocol security
On the Main tab, click
.The Virtual Server List screen opens.
Click the Create button.
The New Virtual Server screen opens.
- In the Name field, type a unique name for the virtual server.
In the Destination Address field, type the IP address in
The supported format is address/prefix, where the prefix length is in bits. For example, an IPv4 address/prefix is 10.0.0.1 or 10.0.0.0/24, and an IPv6 address/prefix is ffe1::0020/64 or 2001:ed8:77b5:2:10:10:100:42/64. When you use an IPv4 address without specifying a prefix, the BIG-IP® system automatically uses a /32 prefix.Note: The IP address you type must be available and not in the loopback network.
- In the Service Port field, type 25 or select SMTP from the list.
- In the Configuration area, for the SMTP Profile setting, select the default profile, smtp.
- From the Source Address Translation list, select Auto Map.
- For the Default Pool setting, either select an existing pool from the list, or click the Create (+) button and create a new pool.
- Click Finished.
Reviewing violation statistics for security profiles
On the Main tab, click HTTP,
FTP, SMTP, or
and click The appropriate statistics screen opens listing all violations for that protocol, with the number of occurrences.
- Type a Support ID, if you have one, to filter the violations and view one in particular.
Click a violation's hyperlink to see details about the requests causing the
On the Statistics screen, in the left column, you can review information regarding the traffic volume for each security profile configured.