WFilter is able logging outgoing mail but not incoming.

General discussion about WFilter ICF features, problems, configuration issues etc.

Moderators: imfirewall, gengw2000

IT-RSMNLK
Posts: 9
Joined: Fri Jul 19, 2013 8:52 am

WFilter is able logging outgoing mail but not incoming.

Postby IT-RSMNLK » Tue Sep 03, 2013 2:50 pm

The question was already on the forum but i found the answer not clear.



This was the answer:

the default exchange server protocol using outlook is not supported because it's traffic is encrypted



Our situation:

WFilter scans a mirror port on a switch. The source is the firewall port that handels all internet traffic.



Everything goes well except the incoming mail. We use Exchange 2010 and Outlook 2010.



Between the internet and the Exchange server there is only a firewall and a Trend Micro mailgateway with no mail encryption.

I understand that we can't read the internal e-mails, but I don't understand why we can read the outgoing mails and not the incoming mails.



In my understanding they take the same road only in opposite directions. Exchange server -> Internet. Internet -> Exchange server.



Especially with the incoming emails from an external source, I can't see why Outlook encryption should be involved.



Can someone help me explain why WFilter can't scan the incoming e-mails?



Kind regards,

Daan Udink

imfirewall
Posts: 153
Joined: Fri Nov 26, 2010 7:41 am

WFilter is able logging outgoing mail but not incoming.

Postby imfirewall » Wed Sep 04, 2013 2:10 am

It depends on the email protocols you're using.



If you use pop3 or imap to receive emails, wfilter can record it.



Exchange server provides multiple connection protocols:

1. default exchange server protocol(encrypted and not supported by wfilter)

2. pop3 -- can be recorded

3. imap -- can be recorded





So it depends on how you setup your outlook client to receive emails.



There is a solution: you can block default exchange server protocol, to force the clients to use pop3 or imap instead. If you like this solution, I can write a guide for you.

IT-RSMNLK
Posts: 9
Joined: Fri Jul 19, 2013 8:52 am

WFilter is able logging outgoing mail but not incoming.

Postby IT-RSMNLK » Wed Sep 04, 2013 11:51 am

We only have our firewall port mirrored. Not the mail server port. Behind the firewall is our TrendMicro IWSS mail gateway. So we only scan mails which are going to or coming from our mail gateway.



We are able to scan the outgoing mails, they go from the mail server to the mail gateway. Why can't we scan the incoming mails wich are going from the mail gateway to the mail server?

Both directions should be SMTP. (Or am I wrong?) And therefore I think readable.



We are not interested in mail between exchange and outlook.

imfirewall
Posts: 153
Joined: Fri Nov 26, 2010 7:41 am

WFilter is able logging outgoing mail but not incoming.

Postby imfirewall » Thu Sep 05, 2013 2:20 am



You intend to monitor smtp relay traffic.



We need to setup such a environment to test. I will let you know the result. It shall take no longer than 2 weeks.

IT-RSMNLK
Posts: 9
Joined: Fri Jul 19, 2013 8:52 am

WFilter is able logging outgoing mail but not incoming.

Postby IT-RSMNLK » Thu Sep 26, 2013 9:54 am

Are there already some results from the test environment?

imfirewall
Posts: 153
Joined: Fri Nov 26, 2010 7:41 am

WFilter is able logging outgoing mail but not incoming.

Postby imfirewall » Fri Sep 27, 2013 9:49 am



The reason is wfilter does not recording incoming SMTP messages.



Now we're thinking about adding a protocol pattern definition to get it supported. I believe we will work out this solution in next Monday.

IT-RSMNLK
Posts: 9
Joined: Fri Jul 19, 2013 8:52 am

WFilter is able logging outgoing mail but not incoming.

Postby IT-RSMNLK » Mon Oct 07, 2013 7:41 am

Thats good to know. Now we know is not the configuration but WFilter doesn't have the feature yet.

Is the feature been put in or are you still working it out?



If so, I would appreciate it if you can give me a message when the update is online.

imfirewall
Posts: 153
Joined: Fri Nov 26, 2010 7:41 am

WFilter is able logging outgoing mail but not incoming.

Postby imfirewall » Tue Oct 08, 2013 6:58 am

It's more complicated than we thought. WFilter is designed to monitor and manage local network client computers' internet usage. However, this smtp relay behavior is smtp requests from internet ip addresses.





So monitoring of incoming smtp requires changes of WFilter basic module design, we plan to add this feature in next 4.1 version. I will let you know when it is ready.

IT-RSMNLK
Posts: 9
Joined: Fri Jul 19, 2013 8:52 am

WFilter is able logging outgoing mail but not incoming.

Postby IT-RSMNLK » Fri Jan 03, 2014 11:05 am

Just read that 4.1 wil come out soon. Do you know if the feature to read incoming smtp will be in this version?

imfirewall
Posts: 153
Joined: Fri Nov 26, 2010 7:41 am

WFilter is able logging outgoing mail but not incoming.

Postby imfirewall » Mon Jan 06, 2014 2:28 am

Yes. We've added this feature in the 4.1 version. And the 4.1 beta2 version will be released in two weeks.



Please notice, even in the 4.1 version, to record incoming smtp, a special setting is still required. Please let me know when you're ready, I will send you a setting file to enable it.


Return to “WFilter ICF”

Who is online

Users browsing this forum: No registered users and 13 guests