Jump to content

TedGlass

Members
  • Posts

    26
  • Joined

  • Last visited

Everything posted by TedGlass

  1. Can anybody comment on whether or not I should see a score column in the mail server protection logs? Retained items with their score?
  2. I upgraded to 6.4 over the weekend from 4.5. Emails that used to get delivered to Outlook's Junk Email folder are now being dumped into user's Inbox. In the Log Files section of the GUI, there are only "rejected" items in the log, no more "retained" items. There is no "Score" column to let me see what each item's score is. With 4.5, anything with a score above 50 would get delivered to the Junk Email folder. Looking at the antispam settings, i see nothing about spam score. When i look at a spam email's headers the bottom shows this: X-ESET-AS: R=OK;S=0;OP=CALC;TIME=1477422965;VERSION=4517;MFE-VER=47;MC=3011984922;TRN=0 X-ESET-Antispam: OK X-EsetResult: clean, is OK X-EsetId: 37303A2971705866647C67 I believe the S is Score, and all the Spam i've been getting says "S=0". I can see loads of rejected emails being rejected because of RBL or cloud blocklists. It's almost like that is the only thing being blocked, and everything else is getting through. Help!
  3. I want to exclude a particular file from being scanned by ESET. The file runs in the user's temp folder, this cannot be modified. When I add the static folder/file path to my policy, it works. But that only works for the particular username I hardcode into the path. I want to be able to set this at the policy level and have it work for all logged in users at the client level. c:\users\username\appdata\local\temp\filename.ext When I use the %temp% variable, it does not work. %temp%\filename.ext How do i make this work? Thanks
  4. This is working now. I should've just read the tooltips that are in the policy editor for ERA 6, they specify what you should be doing. But for anyone having this issue, make sure you are adding some sort of file mask (*.*) after the directory. Thanks again Marcos
  5. I added the exclusions to a policy being applied to clients through ERA 6 (6.2.200). The client side is Endpoint AntiVirus (6.1.2222 or newer). I'll add the \*.* at the policy level and see if that filters down to clients and starts working. Thanks!
  6. Any thoughts on this Marcos? Thanks In Advance
  7. I suppose "applied" isn't the right word. It does get applied at the client level from the policy that's setup in ERA 6, meaning you can see the directories in the exclusion list on the clients. But scans still detect items from the specified directories. See screenshots below. What's odd is it doesn't happen everyday, but about 99% of the time it does. Thanks
  8. Anybody got an idea why my directory exclusions aren't getting applied to the daily scheduled on demand scans? Thanks
  9. That doesn't seem to be working for me. I've got directories specified in the "Paths to be excluded from scanning" area, and the settings are getting applied to clients, but i am still getting on demand nightly scans with results from those excluded directories. HELP!
  10. Using ERA 6, how can i create a custom on demand scan so i can exclude certain directories from daily scanning? When i go into my policy for endpoint antivirus i only get the option to choose from one of the 3 preconfigured scan profiles (currently set to smart scan). How do i modify the smart scan profile to exclude directories, or even create my own profile? The area on the top of the configuration tree to exclude directories apparently only applies to real-time scanning. Thanks
  11. My local customer care is just a reseller, doubtful they'd know anything about the configuration options in Mail Security. Very surprised i never got a response from anyone here. However, I was able to get this working. You have to add your blocklist providers to the "RBL" section not the "DNSBL" section. I never could find anything in the documentation or here on the forums spelling out exactly how things need to be configured.
  12. I can't seem to configure a DNSBL with Exchange 2010 and ESMX 4.5.10023. If i add the DNSBLs inside of Exchange, they don't seem to block anything. But i'd rather add them to ESMX anyways and have it reject mail before it ever gets to Exchange. If i add the DNSBLs inside of ESMX, it also doesn't seem to block anything. I've attached a screenshot of the DNSBL config inside ESMX. I am using the following site to test the zen.spamhaus.org block list. hxxp://www.crynwr.com/spam/ How can i set this up so it will work either configured inside ESMX like it should be, or inside Exchange?
  13. Those DATs worked for me using the ERA Virtual Appliance version 6.1.450. Thanks for the fix.
  14. Will my centOS virtual appliance automatically update itself when 6.2 is released? Or is there some sort of manual upgrade process? If its manual, where do i find the instructions on that? Thanks
  15. Do you have instructions on how to get those DATs installed on the centOS virtual appliance? Thanks
  16. Also still hoping for an update on this. It would be a nice feature for us to use, but we'll obviously need to be able to delete from the list. Thanks
  17. OK, sounds good. If you or someone could please post back to this thread once its gotten resolved that would be excellent. Thanks
  18. Sure, no problem... looks like its still doing it. When i go into the ERA web console. I click Admin->Policies and edit my policy. Then i go into Settings->Web and Email->Web access Protection->URL Address management->Edit. Then i click on "List of blocked addresses" and select Edit. In the Edit list window, there are addresses in the address list, when you click one, the "remove" button is greyed out. The Add button is available, but Edit and Remove are not. I appear to be using ERA Server version: 6.1.450.0 From what i can tell the latest version available for download is 6.1.33.0, so i guess i am getting updates for ERA. Is 450 the latest version? Thanks
  19. Can i get an answer as to whether or not this has been fixed? Or an ETA for when it will?
  20. Did this ever get fixed? I'd like to be able to use this feature but still can't delete an entry once its been added. Thanks
  21. So for whatever reason, it decided to deploy successfully today. Tried a new task this morning and it completed. EEA 6 also. I assume this is some sort of weird caching relating to having the agent deployed to a computer with the same name previously, and it just needed time to work itself out. I did try rebooting the appliance yesterday but it didn't help anything. Any ideas on what caused this and if there's anything i can do next time it happens short of waiting a day? Thanks
  22. I've got ERA 6 running as a VM appliance. I've got about 50 clients that I've been able to successfully deploy the agent and then EEA 6 to. I've got a new laptop that i can't get the agent to deploy to. Unfortunately, when we ordered the laptop it came in as defective, but the agent was deployed to it before it was determined we needed to send it back for replacement. The defective unit was manually added to ERA 6, and the agent deployed successfully. When i got the replacement laptop, i named it the same as the first one. I went into ERA 6 and deleted the entry for the first laptop, then manually added it back with the same name (i assume this is where the problem lies). When i try to deploy to it, the task fails every time with generic error codes. I also tried deleting it again, and adding it using just the IP address instead of Netbios name, but no luck on agent deployment. You can ping from the server appliance command line and resolve the client IP successfully. You can ping from the client and resolve the ERA server IP successfully. IPC$/ADMIN$ shares are operational. No firewall configured. Domain credentials being supplied to the task are the same as used on all the other clients. There's no log inside ProgramData on the client. Client is Win 7 Pro 64bit. Most notably, when you start the task, less than a minute later you see an error show up on the actual VM appliance GUI. It says "CIFS VFS: Send error in SessSetup = -12" and "CIFS VFS: cifs_mount failed w\return code = -12". Screen shot below. I need to get this laptop to someone over the weekend. I have to say, this ERA 6 is beginning to be a real pain! Plenty of potential though...
  23. Ok, thanks for the response. I assume this is something that'll have to be fixed with a future release.
×
×
  • Create New...