• Reading ESA Message Log

    Hi All, I am having some issues parsing the logs from the appliance i've got the majority off them sorted, its just the Message log I am having issues with. Can anyone point me in the direction of a document or let me know what the fields are in log…
  • Netscaler to Load balance Virtual Email Appliance

    Hi Everyone, We are about to configure NetScaler to Load balance (internally) the traffic between two clustered appliances and I wonder if anyone else did it using NetScaler or another LB solution and what recommendations would you have in regards to…
  • bidirectional encryption

    Can anyone tell me requirements and tasks required to implement bi-directional Email encryption on appliance ES4000 Thanks
  • Can I look at every rule that was triggered for a message?

    I am trying to see why my SPF rule flagged an email. When I find the message in the mail logs it shows a different rule being triggered. Is there a way to look at each rule that was triggered?
  • SEA cant connect to sea-dynamic.sophos.com; threat definitions not updated

    Hi All, Email appliance is having trouble connecting to sea-dynamic.sophos.com When I tried pinging sea-dynamic.sophos.com the result is: Pinging sophos.vo.llnwd.net [ 203.77.191.0 ] with 32 bytes of data: Request timed out. Request timed out. Request…
  • FEATURE REQUEST: Email appliance - Import/Export TLS encryption domains

    Hi, As our email domain has been recently assessed by the Government and passed we are required to configure required TLS encryption on all other whitelisted government domains. This is a long list that is constantly updating. The list is provided in…
  • Cannot view message details for quarantined emails

    I've got a few emails that have been quarantined in our email appliance. When I click on the email that's blocked and try and select 'info', the display is completely blank. Clicking on any of the other tabs (body/headers/info) is unresponsive. Thus,…
  • Pull a list of Phishing Campaign IPs

    In regards to recent phishing campaigns that have surfaced (Docusign) we would really like to see the ability to export a list of source IPs so that we can add to the appropriate blocklists. Syslog doesn't appear to log the source IP address along with…
  • Sophos sandstorm feature

    Hi, I had enabled the sandstorm feature in sophos email appliance. I want to disable it for time being. My question is, can i able to enable it again after some days if required. Regards Ansar
  • Unable to access email appliance web interface over wifi/vpn

    Hello, I have a ES1100 that is connect to our palo alto firewall....Not sure if this is even the correct place to post this but I am unable to access the email appliance web interface via WiFi, whether I'm on the the corporate WiFi or whether I'm on…
  • SEA licensing- Confuse

    Currently POC on SEA. All inbound mail flow through SEA for scanning of Antispam, viruses, sandstorm. Then, it relay/forward to Internal Lotus Email Server. There is no Directory integration of AD/ Notes server with SEA. Occasionally, with few manual…
  • SEA Logs File Viewer delay

    Hello, we are running a virtual Appliance v4.2.0.3 and are experiencing a long delay in the log viewer. It takes longer than 2 minutesto log entries show up after a mail is processed by the sea. Is this expected behavior? Best regards
  • SPX attachment did not receive by recipient

    Hi! I made all of the possible adjustment on data control and additional policy in SEA configuration but not successful. My objective is to retrieve the attachment in .doc & .txt format, sent using SPX encryption but all I got is the pdf contains…
  • SEA mail logs for outbound emails

    Hi! I've develop migraine in finding solutions for almost a month now.. I noticed that the mails logs (sender column) does not record the outbound mails but the sender's from external like Gmail can be logged. So basically there are email traffic…
  • Email appliance as second spam filter

    Hi there, We ae trying to implement the Virtual Email Appliance as the second level of email scanning in our infrastructure. As such we have another vendor's spam filters sitting outside our network as the initial filtering point and then we have…
  • Virtual Email Appliance missing the Policy > Anti-Virus settings tab

    Hi there, We have just installed a clustered pair of the Virtual Email Appliance. I am going through initial configuration and I am trying to look at the settings for Anti-Virus but the tab is missing under the policy section. (See screen grab)…
  • Sophos Email Appliances (SEA) - Add ability to create rules that handle mail based on language / character sets

    Currently there is no way to create a rule for handling email sent in different language / character sets. For instance, you cannot create a rule that will block all character sets except English to/from a certain email domain. You also could not currently…
  • Sophos Virtual Email Appliance - Update how appliances handle default email address changes

    We have a pair of Sophos Virtual Email Appliances, clustered, and we use Directory Services to connect to Active Directory and synchronize our customer mailbox accounts. We recently had a customer want to change the format of their email addresses from…
  • Allow/Exclude Non-Existent Domain

    We have an email that is sent by one of our parent groups using a mainframe batch job. The email domain does not exist, and so it is being discarded on arrival. Is there a way to do this without turning off the "Block mail from non-existent domains…
  • Authentication Logs

    I have been seeing several Active Directory account lockouts lately with the source being one of the two Email Appliances that are in place. The existing logs don't seem to show anything related authentication. Is this being logged somewhere or can…
  • External tag - double tagging problem?

    I have an additional policy rule in place to tag all incoming email with an external email notification tag in the subject line. Sometimes when replying to all external users that have been CC'd, and then receiving their reply to that email, subject lines…
  • How do i know whether an email is having attachment or not in logs.

    Hi, I would like to know about is there any way to find out, an email which received to our exchange server is having an attachment or not from Sophos Email Appliance logs. Regards Ansar
  • TLS on a ES1100

    Morning could anyone help with a quick question. what is the version of SSL/TLS that runs or is allowed if the encryption is switched on as tls 1.0 is now being phased out and 1.2 is becoming the standard is it backwards compatable? Many than…
  • PPTX documents being blocked by rule only set to block PPTM documents

    I have a rule configured which blocks various macro-enabled file types. One of these file types include PPTM. Unfortunately, PPTX documents are also being blocked by the same rule. Any Ideas would be greatly appreciated
  • Possible Bug - Security Certificate Issue

    I recently ran into an issue with the Security Certificate, stating "The server you are connected to is using a security certificate that cannot be verified. The target principal name is incorrect." Reviewing the certificate, it said the certificate was…