This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

ES1100 features

Hi All,

Currently im running 1 POC for 1 unit Sophos ES1100 email appliance, below are question raised by customer regarding email appliance feature.

Appreciate if anyone can provide suggestion or guide regarding features as required by customer. Thanks

  1. How to open the attachments of the quarantine mails?
  2. Create/configured to copy every email that go through email appliance?
  3. Copy every mail to external/server so that we will have another copy of the mail?
:20079


This thread was automatically locked due to age.
  • Hi Azwan,

    For question 1, unfortunately it is not possible to open attachments direct from the email appliance GUI at this time.  However, you can view details of the quarantined attachment in 'Search > Quarantine'.  Quarantined e-mails can also be forwarded to an administrator in the same section.

    For questions 2&3, there are a number of methods to create archived copies of e-mails.

    If you want to copy every e-mail I would recommend to create a 'Use Only message attributes' policy in 'Configuration > Policy > Additional Policy'.  If you don't enter any message attributes this policy will affect every e-mail. 

    Alternatively, if you want the policy to only affect specific users/domains you can use a 'Watch list' policy.

    You then have several options available on the actions tabs.  For example:

    Main Actions:

    Quarantine and continue - A copy will be placed in quarantine as well as sent to the user

    Send a copy to another server - A copy will be sent to the specified smtp server in addition to the normal mail delivery server

    Additional Actions:

    Notify - This option allows you to notify a custom e-mail address and optionally include a copy of the original message as an attachment.

    Please note that 'Additional Policies' happen after the virus test, but before the spam test - so spam messages will also be archived.

    Hope this helps, let me know if you have any further queries.

    Tom.

    :20113
  • Hi Tom,

    I have successfully implement additional policy as suggested, customer is asking for offensive langguage policy such as does sophos email appliance can detect bad word on japanese language .

    Currently we in process of POC and customer is comparing ES1100 with MailSweeper (*current user production product), customer is happy in term of features however they are looking for a features to copy all email for troubleshooting & backup .

    Compare to MailSweeper, ES1100 couldn't store all email due to disk space since customer is huge factory and copy of email have to store on ES1100 as per policy requirement (POC setting), user caomplain they have to setup/buy extra hardware to use the features compare with MailSweeper if we use "Send a copy to another server " policy. Thanks

    :20171
  • Tom,

    I know this is an old post.  But you mentioned the "Additional Policy" process after Anti-Virus but before the SPAM test.  What is the thought process behind that design?

    I have wondered why that was but didn't know.  I figured Anti-Virus and Anti-SPAM would process before other policies.  I would think creating Additional Policies would be 3rd or after in line.

    My thoughts would be the "Additional Policies" running prior to Anti-SPAM would be processing, catching, quarantining emails that would otherwise be identified as SPAM and having to sort through it.

    Seems backwards to me but that but that is because I don't understand the logic behind letting Additional Policies take precedence like that.

    Seems like that Additional Policies would process afterward depending on what you are doing with Additional Policies.

    Seems like it would make the Anti-SPAM less effective.

    What is the thought, logic and design process behind why Additional Policies are ran this way.

    Thanks!

    :28167