Skip to main content

LevelBlue Completes Acquisition of Cybereason.  Learn More

LevelBlue Completes Acquisition of Cybereason.  Learn More

Services
Cyber Advisory
Managed Cloud Security
Data Security
Managed Detection & Response
Email Security
Managed Network Infrastructure Security
Exposure Management
Security Operations Platforms
Incident Readiness & Response
SpiderLabs Threat Intelligence
Solutions
BY TOPIC
Offensive Security
Solutions to maximize your security ROI
Operational Technology
End-to-end OT security
Microsoft Security
Unlock the full power of Microsoft Security
Securing the IoT Landscape
Test, monitor and secure network objects
Why LevelBlue
About Us
Awards and Accolades
LevelBlue SpiderLabs
LevelBlue Security Operations Platforms
Security Colony
Partners
Microsoft Security
Unlock the full power of Microsoft Security
Technology Alliance Partners
Key alliances who align and support our ecosystem of security offerings
Loading...
Loading...

FAQ: Why is email blocked by the filter

Expand / Collapse


This article applies to:

  • R3000
  • WF/WFR

Question:

  • Why is my email blocked by the filter? ii it a port block?

Reply:

The reason for the block is not the port but the SSL communication in the packet. The filter tries to get a certificate on all destination domains. The filter will block most SSL traffic when a certificate cannot be matched ip/domain on the smtp ' Helo' to the destination server. We are working to make this more flexible on certificate lookups.

Although this can sometimes lead to overblocking, being port-agnostic is actually one of the advantages of the Web Filter, in that it’s not just looking at the well-known HTTP ports.  There’s nothing to prevent a web server from listening on any port, but many web filtering solutions just monitor a few specific ports.  If the customer encounters issues in this area, they can use the Range To Detect to make the necessary exclusions. 

The range to detect is in Policy>Global Group>Range to detect.

add your Source ip and then go to source exclude and add your server ip's there.

Notes:


To contact Trustwave about this article or to request support:


Rate this Article:
     

Add Your Comments


Comment submission is disabled for anonymous users.
Please send feedback to Trustwave Technical Support or the Webmaster
.