Announcement

Collapse
No announcement yet.

Is Virus Blocker Lite still useful?

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Is Virus Blocker Lite still useful?

    I'm having an issue with Virus Blocker Lite blocking a TLS 'handshake' for just 1 single email domain that our company is working with. It stops all outgoing emails to that domain.

    If I look at the Virus Blocker Lite reporting it seems like it's never blocked anything. We don't own a license for SSL Inspector so it's not really stopping anything in the email department anyway.

    I've tried disabling all three of its scanning options (http, smtp, ftp) and adding the site we are emailing to the 'pass sites'. But we can still not email them if virus blocker lite is running. As soon as I shut it down, we can email them perfectly.

    I hate to turn it off, I feel like even if it caught one virus it would be worth while. Is there anything else I can do, or should I just shut it off?

  • #2
    VB Lite does not look at HTTPS. What protocol is the TLS 'handshake' issue on?
    Attention: Support and help on the Untangle Forums is provided by
    volunteers and community members like yourself.
    If you need Untangle support please call or email [email protected]

    Comment


    • #3
      It's an Exchange server, sending emails so I'm pretty sure it's just port 25. Our spam filter does the TLS/SSL, but I'm not certain if it changes ports to 443 do that or not.

      I do know it's missing the majority of them. VB Lite has scanned 99 messages today but we've received 1300+. Edit: I think the only reason it was 99 is because I was working on updating our email servers TLS cert today, so it was going up and down. Should usually less than 99.
      Last edited by powdermnky007; 01-27-2021, 02:09 PM.

      Comment


      • #4
        VB will abandoned TLS connections on port 25. I have seen issues with malform TLS SMTP and VB. I would just bypass port 25 traffic and do the virus and spam scanning on the server.
        Attention: Support and help on the Untangle Forums is provided by
        volunteers and community members like yourself.
        If you need Untangle support please call or email [email protected]

        Comment


        • #5
          Sounds good, how should I bypass port 25? Thank you in advance.

          Comment


          • #6
            I wouldn't bypass TCP 25, I'd use policy rules to shove it into its own policy. That policy would have apps that are useful for SMTP monitoring, like the firewall app, and perhaps the intrusion prevention module.

            The firewall app alone for the logging is essential for troubleshooting.
            Rob Sandling, BS:SWE, MCP, Microsoft Certified: Azure Administrator Associate
            NexgenAppliances.com
            Phone: 866-794-8879 x201
            Email: [email protected]

            Comment


            • #7
              I definitely want it going through the firewall app. I block all IPs coming from China. Maybe that only stops 10% of spam, but I'll take it. We have zero clients over there.

              Comment


              • #8
                Originally posted by powdermnky007 View Post
                I definitely want it going through the firewall app. I block all IPs coming from China. Maybe that only stops 10% of spam, but I'll take it. We have zero clients over there.
                Then use the policy manager! I do this for ingress EVERYTHING, because if you don't it goes through the same insanity as random web requests going out. That's generally BAD for all sorts of reasons.
                Rob Sandling, BS:SWE, MCP, Microsoft Certified: Azure Administrator Associate
                NexgenAppliances.com
                Phone: 866-794-8879 x201
                Email: [email protected]

                Comment


                • #9
                  Thank you for your help sky-knight! I appreciate it, but is there any way to do it besides the policy manager? The only app we've purchased is the web filter and I won't be able to make any purchases at work for a few months.

                  Comment


                  • #10
                    If you don't have policy manager then your only recourse is bypass.
                    Rob Sandling, BS:SWE, MCP, Microsoft Certified: Azure Administrator Associate
                    NexgenAppliances.com
                    Phone: 866-794-8879 x201
                    Email: [email protected]

                    Comment


                    • #11
                      Thank you, I'll go start reading up on that.

                      Comment


                      • #12
                        Originally posted by jcoffin View Post
                        I would just bypass port 25 traffic.
                        Or you could go the other way, and block the port completely.

                        Literally NOTHING should be using unencrypted SMTP over the internet anymore. It's all ports 465 or 587 now. Anything on 25 is bad news. Port 25 is blocked on my network, and no one has complained about it in years. In fact, it's the only port here right now that's blocked outright for outbound.
                        Five time Microsoft ASP.Net MVP managing a Lenovo RD330 / E5-2420 / 16GB with Untangle 16.5.2 to protect a 1Gbps fiber link for ~450 residential college students and associated staff and faculty

                        Comment


                        • #13
                          TCP 25 is still the primary connection point to an email server. If you're hosting one yourself, most traffic is there.

                          But I agree, authenticated sessions have no place on it. And as much as is possible, TCP 25 even is happening with TLS now.
                          Rob Sandling, BS:SWE, MCP, Microsoft Certified: Azure Administrator Associate
                          NexgenAppliances.com
                          Phone: 866-794-8879 x201
                          Email: [email protected]

                          Comment


                          • #14
                            Already doing both of those suggestions. I have outbound port 25 blocked for all IPs on the network except for the email server.

                            Comment


                            • #15
                              Originally posted by powdermnky007 View Post
                              Already doing both of those suggestions. I have outbound port 25 blocked for all IPs on the network except for the email server.
                              On behalf of the rest of the Internet that will see that much less spam, I thank you.
                              Rob Sandling, BS:SWE, MCP, Microsoft Certified: Azure Administrator Associate
                              NexgenAppliances.com
                              Phone: 866-794-8879 x201
                              Email: [email protected]

                              Comment

                              Working...
                              X
                              😀
                              🥰
                              🤢
                              😎
                              😡
                              👍
                              👎