How do Exchange IMF and Antigen Advanced Spam Manager work together?

Following article explains how Exchange Intelligent Message Filtering (IMF) and Antigen Advanced Spam Manager (ASM) work together. Specifically how SCL ratings are assigned    IMF Options Blocking spam with the IMF is a two-stage process. The filter scans the mail and gives each message a Spam Confidence Level rating from zero to nine, with zero…

3

Notes on the new Antigen Cluster Resource (Antigen 9 SP1 RU5 and above)

Microsoft recently released Rollup 5 for Antigen 9 SP1, which contains a particularly important fix for Exchange 2000 / 2003 clusters. The full issue behind this fix is documented in KB957015. Essentially, the ‘fix’ adds a new Antigen Cluster Resource (‘AntigenClusRes’) to each EVS group. I’d like to add some more meat to the fix…

0

How to determine if Antigen or Forefront Server catch specific malware without paying for a support incident

Hello, my name is Robert McCarthy and I am a support engineer for the Antigen and Forefront Server product set. Since the advent of Antigen, its hallmark feature has been the ability to incorporate multiple third party scan engines into our scan jobs. This makes Antigen, and Forefront Server alike, the most complete antivirus application…

0

Anti-virus Discussion and Troubleshooting Tips

The virus world has always seen a battle between virus makers and anti-virus vendors, each trying to outwit each other through their speed and technology. Antigen and Forefront products incorporate proprietary and 3rd-party anti-virus scan engines that use heuristics and pattern (definition) technology to scan and detect viruses.   When a new virus is released…

4

Licensing in Antigen 9 and Forefront Server Security 10 Products

This blog entry gives you an overview of licensing for Antigen 9 and Forefront Server Security products, such as FSE and FSSP.   Your product’s expiration date can depend on several factors. Historically, Antigen licensing was controlled by a file called license.cfg (located in the product’s main install folder). This file determined whether your installation…

4

The ‘Illegal Mime Header’ Feature – what you need to know

‘Illegal Mime Header’ is an important feature in Antigen/Forefront. This blog entry describes the expected functionality of this feature from the Antigen 9 for Exchange/SMTP with SP1 and Forefront for Exchange RTM (SP0) releases. The ‘Illegal Mime Header’ feature is basically a check on the internet headers of the SMTP message to confirm that they…

2

Where’s my worm gone?

As I’m writing this blog, the Antigen/Forefront Worm List was last updated over 3 months ago. Don’t be alarmed – this is quite normal. The Worm List isn’t really a “scan engine” you see, and doesn’t need to update so often.   And why might that be? Well, let’s examine what the Worm List is…

1

How can I enable “anti-spam” updates in Forefront?

We often get asked how to enable the “anti-spam” feature in Forefront. Well, there isn’t one, so there! That’s the quick answer anyway.   Although its predecessor, Antigen, uses a 3rd-party anti-spam engine, Forefront Server Security for Exchange has no native anti-spam feature. Exchange 2007 provides anti-spam functionality instead, although the Forefront for Exchange installation…

1

Keyword or Content Filtering is greyed-out in Forefront

As part of performance optimisation for Forefront Server Security for Exchange 2007, certain filtering features are disabled on different scanjobs. In terms of the Forefront Server Security Administrator client you will see these options, but they will be greyed-out and are not configurable. Here are the main differences between Edge/Hub and Mailbox servers:   Edge…

1

What would Customer Support need to start troubleshooting an Antigen/Forefront Server issue?

My name is Joe Anderson, and I work with the CSS Security Support Team.   Having firsthand experience with customers, I wanted to give some insight into things that we request when troubleshooting a particular issue. Below, I describe several of the common support scenarios and provide information about the type of diagnostics you will…

0