JNCIS-SEC [ Antispam ]
SPAM is an unwanted message as everyone knows. When SRX detects a message deemed to be spam, it blocks the email message or tags it with a configured string. You can use a 3rd party spam block list (SBL) or create your own (whitelist or blacklist)
A) Server Based Antispam Filtering
Firewall performs SBL lookups through the DNS protocol. The lookups are against the IP address of the sender or the relaying server. Checks are done in the following order;
1) Local whitelist is checked. If there is a match no further check is done. If there is no match
2) Local blacklist is checked. If there is a match, no further check is done. If there is no match
3) SBL server is checked
Configuration
1) Creating a profile
root@host# set utm feature-profile anti-spam sbl profile sblprofile sbl-default-server
5) Configure a UTM policy for SMTP and link with sbl.
Verification Commands
Ternary : 8.8.8.8, Src Interface: fe-0/0/2
B) Local List Antispam filtering
SPAM Message Handling
1) At the connection level
b) Tagging Detected Spam
* Tagging the header