Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 26, 2013, 12:24:37 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
664096
Posts
70638
Topics
145272
Members
Latest Member:
iqhancpu458
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Business / Enterprise Security Products & Services
Comodo AntiSpam Gateway - Hosted Anti Spam Service
CASG Beta 1, Feedback!
« previous
next »
Pages:
1
[
2
]
3
4
Author
Topic: CASG Beta 1, Feedback! (Read 34158 times)
w-e-v
Star Group
Comodo's Hero
Offline
Posts: 1087
BETA FORCE MEMBER
Re: CASG Beta 1, Feedback!
«
Reply #15 on:
October 18, 2011, 12:45:28 PM »
Ive noticed that many incoming mail, just go straight to our mailserver, even not through CASG.
Why does this happen? Is very often that your mailservers are not reachable?
We have configured our mailservers with this priorities:
. mxsrv1.spamgateway.comodo.com (10)
. mxsrv2.spamgateway.comodo.com (20)
. mail.mydomain.com (30)
As you can see, our mailserver has the lowest priority.
So that means that whenever the first two mailservers (by comodo) dont respond, then our mailserver will process directly the messages.
We have received some spam that was directly sent through mail.mydomain.com.
How can this be avoided?
Logged
Kirill Nelinov
Comodo Member
Offline
Posts: 30
Re: CASG Beta 1, Feedback!
«
Reply #16 on:
October 19, 2011, 05:59:57 AM »
Quote from: w-e-v on October 18, 2011, 12:45:28 PM
We have received some spam that was directly sent through mail.mydomain.com.
How can this be avoided?
Hmm... I'm not sure yet how did happen. Let me ask you few questions:
Was it during some specific time period?
Do you still receive it?
Could you please send me source of the received spam message?
Logged
w-e-v
Star Group
Comodo's Hero
Offline
Posts: 1087
BETA FORCE MEMBER
Re: CASG Beta 1, Feedback!
«
Reply #17 on:
October 19, 2011, 02:58:21 PM »
Thank you Kirill,
Ive just sent you 3 spam samples that we received directly bypassing CASG.
We keep getting some of them.
I couldnt send you any spam from today or yesterday because I always delete them.
The 3 samples I sent you through PM, are from another mailbox using the same domain.
Actually, you will have 4 PM with the "bypassed spam". Dont pay attention to the very first one, since it doesnt include the headers. The other 3 PM include their respective headers.
Should I keep posting latest spams that are bypassed?
«
Last Edit: October 19, 2011, 06:01:54 PM by w-e-v
»
Logged
Kirill Nelinov
Comodo Member
Offline
Posts: 30
Re: CASG Beta 1, Feedback!
«
Reply #18 on:
October 20, 2011, 10:06:48 AM »
Thanks, We are investigating.
Yes, please keep posting latest spams
Logged
w-e-v
Star Group
Comodo's Hero
Offline
Posts: 1087
BETA FORCE MEMBER
Re: CASG Beta 1, Feedback!
«
Reply #19 on:
October 20, 2011, 10:23:15 AM »
Quote from: Kirill Nelinov on October 20, 2011, 10:06:48 AM
Thanks, We are investigating.
Yes, please keep posting latest spams
Ok, I will keep posting them as soon as we receive them.
Now what about spam that has been through CASG and were 'caught-missed'?
Can I report those too via PM, or you have an email where can I attach these files?
Logged
Kirill Nelinov
Comodo Member
Offline
Posts: 30
Re: CASG Beta 1, Feedback!
«
Reply #20 on:
October 20, 2011, 10:27:51 AM »
We are releasing new version soon, which will have this functionality in UI.
For now - yes please keep posted.
It would be great if you could mark it as 'caught-missed' and 'mx-skipped'
Logged
w-e-v
Star Group
Comodo's Hero
Offline
Posts: 1087
BETA FORCE MEMBER
Re: CASG Beta 1, Feedback!
«
Reply #21 on:
October 20, 2011, 06:28:25 PM »
Hi,
I have 4 "caught-missed" and 1 "mx-skipped" from today, but I am not able to send the source through the forum because there is a limit of 4,000 characters. And well, apparently the characters in the SPAM samples are more than that.
What do you recommend?
«
Last Edit: October 20, 2011, 06:32:36 PM by w-e-v
»
Logged
Kirill Nelinov
Comodo Member
Offline
Posts: 30
Re: CASG Beta 1, Feedback!
«
Reply #22 on:
October 21, 2011, 07:45:39 AM »
Ok.
We've checked and looks like there where no connectivity issues with our servers.
It means that "mx-skipped" messages where sent directly to your server.
This is possible until you have mail.yourdomain.com as the third MX server.
Spammers also has access to MX and may send spam directly to the third or to all servers in MX.
So if you want to completely avoid this type of spam - remove mail.yourdomain.com from MX.
As for "caught-missed" I think it is better to wait two weeks for a new version.
Logged
w-e-v
Star Group
Comodo's Hero
Offline
Posts: 1087
BETA FORCE MEMBER
Re: CASG Beta 1, Feedback!
«
Reply #23 on:
October 21, 2011, 09:57:05 AM »
Quote from: Kirill Nelinov on October 21, 2011, 07:45:39 AM
It means that "mx-skipped" messages where sent directly to your server.
This is possible until you have mail.yourdomain.com as the third MX server.
Spammers also has access to MX and may send spam directly to the third or to all servers in MX.
Thats what I thought. It makes lots of sense. Thank you Kirill.
Quote from: Kirill Nelinov on October 21, 2011, 07:45:39 AM
So if you want to completely avoid this type of spam - remove mail.yourdomain.com from MX.
I understand your suggestion, and thats something I thought before on doing in order to avoid CASG to be bypassed. However, I didnt delete it, because mail.mydomain.com is the final mail server destination route in the 'Destination routes' field of CASG UI. This is where the mails are delivered from CASG after appropriate filtering of mails.
Thats the reason why I didnt delete mail.mydomain.com from my MX records list.
What can we do in this case?
Quote from: Kirill Nelinov on October 21, 2011, 07:45:39 AM
As for "caught-missed" I think it is better to wait two weeks for a new version.
Ok, I cant wait until the new release!
Logged
Kirill Nelinov
Comodo Member
Offline
Posts: 30
Re: CASG Beta 1, Feedback!
«
Reply #24 on:
October 21, 2011, 10:15:01 AM »
Quote from: w-e-v on October 21, 2011, 09:57:05 AM
because mail.mydomain.com is the final mail server destination route in the 'Destination routes' field of CASG UI.
Ah, let me explain.
Routes should contain exactly the same records as you had in MX before CASG.
We will use these routes to send messages that had passed filters.
And strictly saying your new MX should not contain old destination servers, only mxsrv*.
However here you have choice:
1) Set MX as you did to be completely sure that mail will be delivered even if our network segment (with mxsrv*) is unavailable which is not likely as it is located in US.
2) Remove your destination servers from MX and be fully protected.
«
Last Edit: October 21, 2011, 10:17:42 AM by Kirill Nelinov
»
Logged
w-e-v
Star Group
Comodo's Hero
Offline
Posts: 1087
BETA FORCE MEMBER
Re: CASG Beta 1, Feedback!
«
Reply #25 on:
October 21, 2011, 10:23:23 AM »
Quote from: Kirill Nelinov on October 21, 2011, 10:15:01 AM
However here you have choice:
1) Set MX as you did to be completely sure that mail will be delivered even if our network segment (with mxsrv*) is unavailable which is not likely as it is located in US.
2) Remove your destination servers from MX and be fully protected.
I completely understand, and I definitely want choice No. 2.
But what I dont understand is, that if I "remove my destination servers from MX", that means mail.mydomain.com will not exist anymore. How can CASG deliver the messages that where filtered to our servers if mail.mydomain.com doesnt exist anymore?
Logged
Kirill Nelinov
Comodo Member
Offline
Posts: 30
Re: CASG Beta 1, Feedback!
«
Reply #26 on:
October 21, 2011, 10:26:10 AM »
CASG will deliver taking destination not from MX but from routes you enter in CASG UI
Logged
w-e-v
Star Group
Comodo's Hero
Offline
Posts: 1087
BETA FORCE MEMBER
Re: CASG Beta 1, Feedback!
«
Reply #27 on:
October 21, 2011, 10:32:59 AM »
So actually the destination route in CASG UI (which right now I have configured is mail.mydomain.com) its only used by CASG to resolve the IP and forward messages to that IP through the port configured, am I right?
I thought that the destination route in CASG UI was and should be the MX record from the server.
Logged
Kirill Nelinov
Comodo Member
Offline
Posts: 30
Re: CASG Beta 1, Feedback!
«
Reply #28 on:
October 21, 2011, 11:10:54 AM »
Quote from: w-e-v on October 21, 2011, 10:32:59 AM
So actually the destination route in CASG UI (which right now I have configured is mail.mydomain.com) its only used by CASG to resolve the IP and forward messages to that IP through the port configured, am I right?
Yes
Quote from: w-e-v on October 21, 2011, 10:32:59 AM
I thought that the destination route in CASG UI was and should be the MX record from the server.
Should be the
old (original)
MX record
Logged
w-e-v
Star Group
Comodo's Hero
Offline
Posts: 1087
BETA FORCE MEMBER
Re: CASG Beta 1, Feedback!
«
Reply #29 on:
October 21, 2011, 11:13:49 AM »
Great! Thanks Kirill for your help and vital information.
I already made the changes and deleted the MX record for mail.mydomain.com
Now there should be no more direct spamming!
Hopefully I did everything in the right way.
I just hope not to loose messages that people send us.
I will let you know how it goes with the new changes. Thanks again!
Logged
Tags:
Pages:
1
[
2
]
3
4
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.055 seconds with 20 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com