Trend Micro™ Scanmail™ for IBM Domino™ Administrator's Guide
Total Page:16
File Type:pdf, Size:1020Kb
Trend Micro Incorporated reserves the right to make changes to this document and to the products described herein without notice. Before installing and using the software, please review the readme files, release notes, and the latest version of the Administrator’s Guide, which are available from the Trend Micro Web site at: www.trendmicro.com/download/documentation/ NOTE: A license to the Trend Micro Software usually includes the right to product updates, pattern file updates, and basic technical support for one (1) year from the date of purchase only. Maintenance must be renewed on an annual basis at the Trend Micro then-current Maintenance fees. Trend Micro, the Trend Micro t-ball logo, and ScanMail are trademarks or registered trademarks of Trend Micro, Incorporated. All other product or company names may be trademarks or registered trademarks of their owners. This product includes software developed by the University of California, Berkeley and its contributors. All other brand and product names are trademarks or registered trademarks of their respective companies or organizations. Copyright© 2013 Trend Micro Incorporated. All rights reserved. No part of this publication may be reproduced, photocopied, stored in a retrieval system, or transmitted without the express prior written consent of Trend Micro Incorporated. Document Part No. SNEM55971_130516 Release Date: September 2013 Protected by U.S. Patent Nos. 5,951,698 and 5,889,943 i Trend Micro™ ScanMail™ for IBM Domino™ Administrator’s Guide The Administrator’s Guide for ScanMail for IBM Domino introduces the main features of the software and provides installation instructions for your production environment. Read through it before installing or using the software. Please refer to Getting Support for technical support information and contact details. Detailed information about how to use specific features within the software is also available in the Help Database and online Knowledge Base at Trend Micro’s Web site. Trend Micro is always seeking to improve its documentation. If you have questions, comments, or suggestions about this or any Trend Micro documents, please contact us at [email protected]. Your feedback is always welcome. Please evaluate this documentation on the following site: www.trendmicro.com/download/documentation/rating.asp ii Preface Preface This Administrator’s Guide describes ScanMail for IBM Domino (SMID) and provides installation and uninstallation instructions to help you configure SMID functions for your specific needs. The ScanMail Administrator’s Guide discusses the following topics: • Introducing ScanMail and ScanMail Suite for IBM Domino 5.6 provides an overview of the product and description of all new features in this release. • Installing ScanMail for IBM Domino provides step-by-step instructions on installing ScanMail for IBM Domino. • Getting Started with SMID provides recommended procedures to configure SMID after you have installed it. • Configuring Scan Tasks provides procedures to create policies, rules, or expressions that SMID will use to protect a Domino environment. • Performing Administrative Tasks provides procedures to monitor server status and create rules for individual or groups of Domino servers. • Updating Components provides procedures to update antivirus and content security components. • Sending ScanMail for IBM Domino Notifications provides procedures to send ScanMail notifications. iii Trend Micro™ ScanMail™ for IBM Domino™ Administrator’s Guide • Using the Log and Quarantine Databases provides procedures to maximize the use of the ScanMail Log and Quarantine databases. • Using ScanMail for IBM Domino with Trend Micro Control Manager provides details on how to use Trend Micro Control Manager™ to manage ScanMail. • Removing SMID provides procedures for removing ScanMail for IBM Domino. • Troubleshooting provides troubleshooting tips. • Getting Support provides guidelines to get more information. Additionally, the ScanMail Administrator’s Guide contains the following appendices: • Understanding Threats in a Domino Environment provides information on the types of threats found in a Domino environment. • ScanMail for IBM Domino Best Practices provides installation instructions to improve operation and obtain maximum performance for SMID. • Program File and Folder Lists provides a list of the SMID and Control Manager files and folder structures that are available upon a successful application installation. • SMLD 5.5 and SMID 5.6 Feature Comparison provides a comparison of ScanMail for Lotus Domino 5.5 and ScanMail for IBM Domino 5.6 features. iv Preface What’s New in Version 5.6 ScanMail for IBM Domino represents a significant advancement in anti-malware, Advanced Persistent Threat (APT) Prevention, content security, and data loss prevention for IBM Domino environments. ScanMail Suite for IBM Domino provides state-of-the-art detection based on heuristic rule-based scanning, recognition of Approved/Blocked Senders lists and signature databases. It also includes anti-spam, content filtering, and data loss prevention that may be applied according to the needs of your organization. Note: IBM has changed its product name from IBM Lotus Domino to IBM Domino since the release of Domino 9.0. From version 5.6, Trend Micro renames ScanMail for Lotus Domino (SMLD) to ScanMail for IBM Domino (SMID) accordingly. Configuration improvements make SMID more flexible and scalable than ever before. • Enhanced Web Reputation • Enhanced Approved/Blocked Lists • Log Search • Enhanced APT Prevention • Enhanced EUQ • Enhanced Macro Scan • IBM Domino 9.0 Support • IPv6 support Enhanced Web Reputation Web reputation scanning can provide the latest protection against Web threats and attacks based on Trend Micro's Smart Protection Networks (SPN). In this version of ScanMail, category information about malicious URLs, for example, social and porn sites, will be provided in web reputation detection logs. Moreover, for performance consideration, administrators are allowed to choose the type of messages that will be scanned by Web Reputation. For example, they can choose only to scan SMTP mails to save resources. After scanning, notification for web reputation detection will be provided. v Trend Micro™ ScanMail™ for IBM Domino™ Administrator’s Guide Enhanced Approved/Blocked Lists In previous ScanMail versions, there is a size limit for both Approved/Blocked Senders list in Anti-spam filter and Approved URL list in Web Reputation. In this version, those lists that are redesigned have no size limit. Log Search In previous ScanMail versions, the log database (smvlog.nsf) cannot be searched. The log search function is critical for security incident investigation. In this version, the log search function is provided, and search conditions are configurable. For details about the log search function, see Searching for Logs on page 8-5. Enhanced APT Prevention From version 5.5, ScanMail is integrated with Advanced Threat Scan Engine (ATSE) and Deep Discovery Advisor (DDA) for Advanced Persistent Threat (APT) prevention. With the help of the latest sandbox technology, DDA will return the detection result for unknown risks and zero-day attacks, including the security risk level. In this version, administrators are allowed to set their own APT prevention level. More and more email attacks come from specific countries. This version of ScanMail can block email attacks from those countries by checking character sets. Enhanced EUQ In SMLD 5.5, if you enable the End User Quarantine (EUQ) feature, it will be applied to all users. In SMID 5.6, the feature has been enhanced to apply to targeted users/groups and mail templates. Enhanced Macro Scan Macro scan uses heuristic scanning to detect macro viruses/malware and strips all detected macro codes. This version allows administrators to configure the heuristic level for macro scan. IBM Domino 9.0 Support This version of ScanMail supports the latest IBM Domino 9.0. vi Preface IPv6 support This version of ScanMail supports IPv6. Audience ScanMail for IBM Domino documentation assumes a basic knowledge of security systems and administration of IBM Domino™ email and information sharing system functions. The Administrator’s Guide and Domino-based online Help are designed for Domino and network administrators. Document Conventions To help you locate and interpret information easily, the ScanMail documentation (Help and Administrator’s Guide) uses the following conventions. TABLE 1-1. Conventions used in SMID documentation CONVENTION DESCRIPTION ALL CAPITALS Acronyms, abbreviations, and names of certain com- mands and keys on the keyboard Bold Menus and menu commands, command buttons, tabs, options, and ScanMail tasks Monospace Examples, sample command lines, program code, and program output Configuration notes Note: Recommendations Tip: Reminders on actions or configurations that should be WARNING! avoided vii Trend Micro™ ScanMail™ for IBM Domino™ Administrator’s Guide viii Contents Contents Preface What’s New in Version 5.6 ............................................................................ 1-v Audience ......................................................................................................... 1-vii Document Conventions .............................................................................. 1-vii Chapter 1: Introducing ScanMail and ScanMail Suite for IBM Domino 5.6 Product Overview ........................................................................................... 1-2 ScanMail