Email Security Dell SnicWALL Email Security 8.0 SnicOS Cntents System Cmpatibility... 1 Enhancements in Email Security 8.0... 3 Knwn Issues... 13 Reslved Issues... 13 Upgrading t Email Security 8.0... 14 Related Technical Dcumentatin... 17 System Cmpatibility Fr Appliances Dell SnicWALL Email Security 8.0 firmware is supprted n the fllwing appliances: Dell SnicWALL Email Security 200 Dell SnicWALL Email Security 300 Dell SnicWALL Email Security 400 Dell SnicWALL Email Security 500 Dell SnicWALL Email Security 4300 Dell SnicWALL Email Security 6000 Dell SnicWALL Email Security 8000 Dell SnicWALL Email Security 8300 Fr Sftware When installed as sftware, Dell SnicWALL Email Security 8.0 is supprted n systems that meet the fllwing requirements: Operating Systems: Windws Server 2008, R2 (64-bit) Windws Server 2012 (64-bit) Nte: Dell SnicWALL Email Security 8.0 Sftware is nt supprted n Windws running n VMware. Use the Email Security Virtual Appliance n VMware platfrms. Hardware Requirements: Intel Pentium: P4 r cmpatible CPU 4 GB f RAM Hard Disk: Additinal 160 GB minimum. Recmmended installatin n a separate drive. Yur strage needs are based n yur mail vlume, quarantine size, archived data, and auditing settings.
Fr Virtual Appliances Release Ntes When installed as a Virtual Appliance, Dell SnicWALL Email Security 8.0 is supprted n systems that meet the fllwing requirements: VMware Platfrms: ESX 5.1 and newer Hardware Resurce Requirements: 160 GB thick prvisined hard disk space Nte: The OVA image fr the Dell SnicWALL Email Security Appliance specifically allcates 160 GB n the virtual disk and cannt be altered. 4 GB RAM 1 CPU 2
Enhancements in Email Security 8.0 The fllwing is a list f new enhancements made t features in the Dell SnicWALL Email Security 8.0 release: Encryptin Service The Encryptin Service feature wrks in tandem with Dell SnicWALL Email Security as a Sftware-as-a- Service (SaaS), which prvides secure mail delivery slutins. The mail messages that have [SECURE] as part f the Subject will be encrypted and securely delivered t the recipient via the Encryptin SaaS. The Encryptin Service wrks with bth utbund and inbund email messages. The Encryptin Service must first be licensed thrugh the System > License Management page. The administratr then will enable the default plicy filter that enables sending secure mail via the Encryptin Service. After adding the necessary sender dmains and public IP addresses, the administratr can then add users that are licensed t use Encryptin Service. 3
The Encryptin Service als supprts Whitelist IP Addresses. Send Secure Mail Buttn The Dwnlads page n yur Email Security slutin prvides a link fr the Send Secure buttn fr Micrsft Outlk. This buttn allws yu t send Secure Mail messages using the Encryptin Service. T install, simply click the link cmpatible with yur versin f Outlk. 4
The Send Secure buttn displays n yur Outlk prgram where the Send buttn previusly was lcated. Yu can als access the Dwnlads page by clicking the Dwnlad Anti-Spam Applicatins link frm yur Junk Bx Summary messages: Allwed IP Address Supprt Enter a list f public IP addresses that are respnsible fr delivering utging mail recgnized as secure. Then, enter the IP address and any assciated dmain that is respnsible fr receiving incming mail messages frm the Encryptin Service. Nte that if n inbund addresses are specified, the MX Recrds are used instead t deliver mail messages t yur rganizatin. 5
DMARC Plicy Enfrcement Dmain-based Message Authenticatin, Reprting & Cnfrmance (DMARC) is a plicy that wrks in tandem with the SPF and DKIM features t fully authenticate incming and utging email messages. Navigate t the Anti-Spfing > Inbund tab t cnfigure settings fr DMARC Plicy Enfrcement fr incming messages. By default, the DMARC feature is enabled. Yu can specify the exact dmain names t exclude frm DMARC Plicy Enfrcement. The DMARC feature als allws yu t specify dmains fr Incming and Outging message reprts. If yu chse t cnfigure Incming/Outging reprts, yu can view the results n the Reprts & Mnitring > DMARC Reprting page. DMARC Reprting The Reprts & Mnitring > DMARC Reprting page allws yu t generate varius DMARC reprts. Navigate t the Reprts & Mnitring > DMARC Reprting > Cnfigure Knwn Netwrks page t add server grups and IP addresses t be generated in the selected reprts. Knwn Netwrks are cnsidered IP addresses wned by Email Security servers, and IP addresses nt wned are cnsidered Unknwn Netwrks. 6
DKIM fr Outbund Email Dell SnicWALL nw supprts DKIM fr utbund email messages. Dmain Keys Identified Mail (DKIM) uses a secure digital signature t verify the dmain name f the email message, which is then validated by the recipient f the message. Outbund email messages nw include DKIM signatures added t the headers f the messages. T cnfigure the settings fr DKIM Outbund Signatures, navigate t the Anti-Spfing > Outbund tab, and click Add Cnfiguratin buttn in the DKIM Signature Cnfiguratins sectin. 7
Smart Hst Ruting Using Multiple IPs The Smart Hst Ruting feature nw includes ptins t use rund-rbin r failver mde t rute mail t multiple destinatin servers. This feature is currently supprted n the inbund path dialg nly. Yu can cnfigure the Smart Hst Ruting settings by navigating t the System > Netwrk Architecture > Server Cnfiguratin page and clicking Add Path. 8
Exprt Address Bk The Exprt Address Bk ptin fr Glbal Administratrs and OU Administratrs is nw available. Navigate t the Anti-Spam > Address Bks page. Click the Exprt buttn. The available address bk is exprted t yur lcal system as a.txt file. 9
Likely Spf Judgment Inbund Plicy Release Ntes A Likely Spf Judgment Inbund plicy is nw supprted n the Plicy & Cmpliance > Filters page. Select the Inbund tab and the Add New Filter dialg bx displays. Fr Select, chse the Likely Spf Judgment ptin frm the drp dwn list. Yu can then select the specific Matching field fr likely spf judgment. Drag-and-Drp Plicy Filter The Plicy & Cmpliance > Filters page allws yu t select any filter frm the list and drag and drp it int a different psitin n the list. IPv6 Supprt Dell SnicWALL Email Security nw supprts IPv6 cnfiguratin. System Diagnstics Enhancements Dell SnicWALL Email Security supprts the fllwing categries fr diagnstics n the System > Diagnstics page: Run SMTP Test fr specific Hst r IP Query DNS fr A Recrd f the specified Hst Query DNS fr MX Recrd f the specified Hst Query DNS fr SPF Plicy fr the specified Hst Query DNS fr DMARC Plicy f the specified Hst Query DNS fr DKIM Plicy f the specified Hst Ping the specified Hst r IP Cnnect t the specified Hst 10
Per Dmain TLS Supprt Administratrs are nw able t cnfigure per-dmain and per-path Transprt Layer Security (TLS). This allws the administratr t specify dmains fr which upstream r dwnstream TLS is mandatry. SPF UI Enhancements Sender Plicy Framewrk (SPF) is an email validatin system designed t prevent email spam by detecting email spfing by verifying sender IP addresses. SPF recrds, which are published in the DNS recrds, cntain descriptins f the attributes f valid IP addresses. SPF is then able t validate against these recrds if a mail message is sent frm an authrized surce. If a message des nt register as an authrized surce, the message 'fails.' Yu can cnfigure the actins against messages that 'fail.' There are tw types f SPF Fails: SPF SftFail - If the email message frm a dmain riginates frm an IP address utside f the IP range defined in the SPF recrd fr the dmain, the message is accepted, but marked. SPF HardFail - If an email message frm a dmain riginates frm an IP address utside f the IP range defined in the SPF recrd fr the dmain, the message is rejected. The Anti-Spfing > Inbund tab allws yu t cnfigure setting fr SPF Hard Fail and SPF Sft Fail. The SPF enhancements nw include cnfiguring the actins fr SPF Hard Fail and adding dmain(s) fr this specific fail. Fr SPF Sft Fails, yu can cnfigure Ignre Allw Lists. 11
12
Knwn Issues The fllwing are Knwn Issues in the Email Security 8.0 release: Symptm 143722 IPv4 must be cnfigured n Ethernet 1 prt befre IPv6 addresses can be added. Cnditin Occurs when adding an IPv6 alias fr the Ethernet1 prt n the Hst Cnfiguratin page. The Web UI will display that the alias has been successfully added. Hwever, upn scrlling t the Netwrk Settings sectin shws that all the fields are greyed ut and nthing has been cnfigured. Wrkarund: Enter an unused IPv4 address. 143432 Diagnstics page des nt supprt IPv6. Occurs when attempting t use IPv6 addresses n the Diagnstics page. Open SSL 1.0.1g Issue Issue A small number f vendrs may fail t accept default TLS cnnectins frm OpenSSL 1.0.1g. Cnditin Dell SnicWALL Email Security 8.0 uses the mst recent OpenSSL 1.0.1g t initiate TLS cnnectins when delivering email in MTA mde. When such a TLS cnnectin is initiated t cnnect t a small number f vendr slutins, their slutin may fail t accept the default cnnectin. This might result in failure f mail delivery when mandatry TLS is cnfigured and a clear text delivery when an pprtunistic TLS is setup. Recipients experiencing this issue shuld refer t their vendr fr the latest update n this issue. Reslved Issues The fllwing are Reslved Issues in the Email Security 8.0 release: Symptm 141299 Tmcat des nt start after dwngrading Email Security t a pre-email Security 7.4.6 versin. Cnditin Occurs when dwngrading Email Security 8.0 t a release earlier than Email Security 7.4.6. After the dwngrade, Tmcat will nt start and its lg will shw duplicate 8.0 ciphers. Email Security 8.0 nly supprts dwngrading t Email Security 7.4.6. Wrkarund: Manually delete the 8.0 ciphers tag using a text editr. 13
Upgrading t Email Security 8.0 Release Ntes The fllwing prcedures are fr upgrading an existing Email Security appliance r sftware installatin, r fr installing the Email Security Virtual Appliance. Backing Up Yur Existing Envirnment n an Email Security Appliance... 14 Upgrading Yur Existing Dell SnicWALL Email Security Firmware... 15 Upgrading Yur Existing Dell SnicWALL Email Security Sftware... 15 Installing the Dell SnicWALL Email Security Virtual Appliance... 16 Backing Up Yur Existing Envirnment n an Email Security Appliance Befre yu upgrade yur appliance firmware, yu shuld back up yur existing envirnment. This will enable yu t restre it if yu decide t change back fr sme reasn. Yur backup shuld include the settings files, including the per user settings. T back up yur existing envirnment: 1. Lgin t Email Security interface using the admin accunt 2. In the left navigatin pane under System, chse Backup/Restre. Yu will see the Backup/Restre page: 3. In the Manage Backups sectin, select Settings. 4. Click Take Snapsht Nw t create a snapsht. 5. Click Dwnlad Snapsht t save the snapsht t yur lcal file system 14
Upgrading Yur Existing Dell SnicWALL Email Security Firmware Fllw this prcedure t upgrade yur existing Email Security firmware n Email Security appliances. Nte: Upgrading yur existing installatin t Dell SnicWALL Email Security Sftware 8.0 is supprted nly if yu are running previus versins n a 64-bit Windws perating systems, which are listed under the System Cmpatibility sectin f this dcument. Dell SnicWALL Email Security 8.0 is nt supprted fr 32- bit perating systems. 1. Navigate t the System > Advanced page and scrll dwn t the Uplad Patch sectin. 2. Click Chse File t lcate the Email Security Firmware file n yur lcal file system, and then click Apply Patch. 3. As part f the upgrade prcess, the Email Security appliance will rebt. The upgrade prcess culd take between 10-20 minutes. All the settings and data will be preserved. NOTE fr ES8300 Yur ES8300 is equipped with a battery backup unit n the RAID Cntrller Card, which allws the appliance t write vlatile memry t disk in the event f a lss f pwer. This battery backup unit must be charged fr 24 hurs. When deplying yur ES8300 appliance, fllw the startup and registratin instructins detailed in the Getting Started Guide, and then allw the battery backup in the unit t charge fr 24 hurs. If the battery is nt fully charged, sme RAID features are turned ff, and the appliance perfrmance is temprarily impaired until the battery is fully charged. Upgrading Yur Existing Dell SnicWALL Email Security Sftware Fllw this prcedure t upgrade yur existing Email Security installatin. The Full Installer includes installatin f Apache Tmcat, the Java Runtime Envirnment (JRE), Firebird, and MySQL as well as the base Email Security sftware. 1. On the server running Email Security, duble-click the Email Security installatin file. Click Run in the dialg bx. If yu d nt have direct access t the server, use a remte desktp cnnectin t cnnect t the server and run the installatin file n the server. Nte: Administratrs must cpy the installatin file t the Email Security Server in rder t run the installatin file. Administratrs will nt be able t upgrade thrugh the Web UI n Windws. 2. In the Welcme page f the installatin wizard, click Next. 3. Read the License Agreement and then click Next t accept the agreement. 4. Dell SnicWALL recmmends that Asian language packs be installed, and an alert is displayed if they are missing. T prceed with the Email Security installatin and install Asian language packs later, click Next. T install Asian language packs prir t prceeding, click Cancel. Nte: Installing Asian language packs is ptinal; hwever, the spam preventin capabilities f Dell SnicWALL Email Security may be diminished withut them. Asian language packs can be installed befre r after Email Security Sftware installatin. 15
5. On the Destinatin Flder page, click Brwse t select an alternate flder, r click Next t accept the default lcatin. Nte: It is imprtant that this flder is nt scanned by an anti-virus engine. 6. On the Chse Data Flder page, click Brwse t select an alternate flder, r click Next t accept the default lcatin. If the data flder is n a different disk drive than the install directry, ensure that it has fast read/write access with less than 10 millisecnd latency. Yu can test latency with the ping cmmand. 7. On the Start Installatin page, click Next. 8. If requested, allw the installatin f Tmcat, Firebird, and the Java Runtime Envirnment (J2RE). If Tmcat is installed in this step, it prmpts fr the Apache Tmcat Web server prt number. The default prt is 80. If yu are already running a Web server n prt 80, yu must change the prt setting. Dell SnicWALL recmmends prt 8080. Click Next t cntinue. Nte: Yu can change the prt number and cnfigure HTTPS access after installatin by using the Server Cnfiguratin > User View Setup page f the Email Security appliance. 9. After the installatin finishes, click Finish in the Installatin Cmplete wizard. A brwser windw is displayed with links t the Email Security user interface and dcumentatin. Installing the Dell SnicWALL Email Security Virtual Appliance Fr infrmatin abut installing Dell SnicWALL Email Security 8.0 as a Virtual Appliance, see the Email Security Virtual Appliance Getting Started Guide, available at: http://www.snicwall.cm/app/prjects/file_dwnlader/dcument_lib.php?t=pg&id=45 16
Related Technical Dcumentatin Release Ntes Fr basic and advanced deplyment examples, Dell SnicWALL dcumentatin is available in the Dell SnicWALL Technical Dcumentatin Online Library: http://www.snicwall.cm/us/supprt.html Last updated: 4/22/2014 17