SurfControl E-mail Filter 5.5 for SMTP Readme
Including Hot-fixes 1-3

February 2007

Welcome

Welcome to SurfControl E-mail Filter 5.5 for SMTP. This release contains the enhancements and fixes listed below. SurfControl Technical Support can be contacted by phone or e-mail.

SurfControl E-mail Filter for SMTP messaging security software offers continuous protection against inbound and outbound threats. Easy to install and administer, the solution’s automatically updated databases, flexible policy setting and market-leading reporting combine best-in-class protection with exceptional visibility and control.

This latest release offers significant enhancements to the reporting capability, extended end-user control and richer message search capabilities delivering increased threat visibility, improved corporate governance, lower administration burden and associated reduced cost of ownership.

New Features in SurfControl E-Mail Filter 5.5 for SMTP

Message Search

The addition of multiple search criteria enables you to quickly search for messages based on sender, recipient and/or date-range information. You can search for inbound and/or outbound e-mails within supplied, selectable date ranges, or your own custom date range. You can also select to search using friendly names and/or e-mail addresses.

You can also restrict which remote administrators have access to the Message Search function. This gives you greater control of system administration.

Message History

You can examine the details of an individual e-mail. This could be useful for helping your Support department or Helpdesk to track problems with e-mail processing. You can also save this information to various formats (such as HTML, TXT, and so on), which enables you to forward the details to other interested parties.

Administrator Alerts

You can select to notify an e-mail administrator if the number of e-mails in the Receive, Rules and Send folders is reached. This can enable your administrators to control system resources.

Improved Message Administrator Interface

The Message Administrator now has an easier to use interface in a logical, intuitive display. This helps you to navigate more easily through queues and logs.

Additionally, new date range filters have been added that improve performance by reducing the total number of entries that are displayed at once.

Note: If you are unable to see entries within a queue or log, ensure that you have the appropriate date range filter selected. For performance reasons, the default date filter for both queues and logs is ‘Today’.

Auditing of Personal E-mail Manager (PEM) User Actions

Audit Queues can be created and configured to store copies of messages that are released or deleted by PEM users. This can be used to review the contents of a message after the message has been released or deleted by a PEM user and for example, to prove a breach of your AUP.

Policy Types in Rule Groups

The Rules Administrator displays policy types (Confidential, Network Security, Virus, and so on) for each Rule Group. Policy Types enable you to quickly determine the categories of e-mails within E-mail Filter queues and logs, and the number of e-mails within specific categories.

These Policy Types are also used by the SurfControl Report Central (SRC) and Personal E-mail Manager (PEM).

Easier Navigation of Logs

The existing Traffic log has been split into two areas:

·          Connection log – For Directory Harvest Detection, Denial of Service, and so on.

·          Receive log – E-mails that have been received by the Receive service.

The existing Rules log has been split into two areas:

·          Rules log – Now only contains rule violations.

·          Audit log – An entry is created when an e-mail is deleted or released from a queue in Message Administrator, by Auto Queue Management or in PEM.

There is also a new Send log, which contains e-mails that have been processed by the Send service. This enables you to see if a message has been sent.

You can view logs for various time periods; today, last 7 days, and so on.

The Policy Type is always displayed in the logs.

You can limit the number of pages of logs that are displayed, and the number of logs within each page. This ensures that you have full control over the display.

Compatible with SurfControl Report Central (SRC) v2.5

The new features of SurfControl E-mail Filter v5.5 enable you to take advantage of the enhanced reporting capabilities of SurfControl Report Central v2.5, which includes drill-down reporting.

Compatible with SurfControl Personal E-mail Manager (PEM) v1.0

The new features of SurfControl E-mail Filter v5.5 enable you to take advantage of the enhanced blocked e-mail controls in SurfControl Personal E-mail Manager v1.0, which includes assigning E-mail Filter queues for PEM, enabling your users to have control of their own blocked e-mails, and so on. PEM v1.0 is a replacement for End-User Spam Management (EUSM).

Bug Fixes

SurfControl E-mail Filter 5.5 for SMTP contains the following bug fixes:

Description

Issue Number

Defects Fixed in 5.5 and Hot-fix 1

SurfControl E-mail Filter should be able to unzip RAR compressed files.

4956

Connection log should show denied connections.

9000

Scheduler events are logged twice.

12953

Allow preference-based selection of multiple static routes.

13622

Rules Service could not create lock file.

13855

Handle paged results from LDAP server in Group lookup code.

13926

Queue Sync + Auto Queue Management conflict

14017

Long BCC recipients list causes STEMRules to crash.

14122

SchedService hangs in stopping state.

14223

Message Administrator does not display e-mails after an SQL server restart

14240

Scheduler - 11th item corrupts Scheduled entries

14518

XML parser cannot handle certain characters in ASA XMLs and dictionaries.

14839

Extra tab stop is added to the subject line when using the Header Modification rule.

15320

Make Release All button look less like the Rules Administrator button.

15365

Remote User Auth Importing from txt file breaks all passwords

15520

Attached message turned to bad when processed by the HTML Parser.

15799

E-mails with *.uue attachments will cause Rules service to fail.

16087

Some Receive service counters not displaying activity in the Performance Monitor

16103

Text file with the letters FWSM mistaken as a shockwave file.

16151

SEF rules service crashes after 10 seconds if queues folder is too large.

16542

Notifications are generated even if the ‘Notify System Administrator if a Scheduler event fails’ check box is cleared.

16603

Message Administrator logs do not show all results.

16616

Improve Send service logging regarding returned error codes.

16642

LexiMatch rule causes Heuristic false positive.

16719

Blind copy PI causes DIR folders to be left in \Work folder after installing service pack 3

16816

Rules crash and bad files.

16820

When appending text to the Subject with ISO 8859-1 format, underscore characters get added incorrectly.

16840

Attached UUE message causes Rules service to hang and then fail.

16844

E-mails turn bad due to large or other HTML files.

16929

E-mails turn bad due to Document Decomposition.

16932

Dictionary Scan + Strip Attachment + Dictionary Threshold will cause BAD file

17240

Remove Reverse Logic option from right-click menu in Rules objects.

18367

Temp files created in the root directories of drives on the E-mail Filter server.

19197

Cab file hangs the Administrator service when it is accessed through Message Administrator.

19477

E-mails turn bad due to certification/encryption.

20035

Send service TCP reset frames.

20037

Max e-mail size limit and non-ESMTP mail servers causes messages to be requeued.

20310

E-mails turn bad due to ISO 2022 CN encoded attachment file names.

20311

Scheduler leaving .tmp files in temp file location

20754

Upgrade from v5.0 to v5.2/v5.2.1 – Pipelining and chunking not disabled even with registry key inserted.

20875

System log fills up with pre-screening logging.

21041

Case-sensitive Directory Harvest Detection (DHD) issue

21099

SPF error – malformed domain.

21254

Incorrect TLS error in Send panel when sending to a cached, non-existent domain.

22120

Send service cannot recognize STARTTLS response if ‘250 STARTLS’ is the last line.

22202

E-mails turn bad due to a Heuristic rule.

22222

E-mail causes immediate access violation in the Rules service.

23786

During an upgrade, the Queue Synchronization process is slow if the Rules Service is processing messages at the same time.

25498

Internet Threat Database is now isolating HTML messages with link text.

25509

The 'To' field in Web Administrator is blank for all isolated messages.

25530

Cannot upgrade if the DSN or database names are changed from STEMLog and STEMConfig.

25534

DictionaryScannerPI is not loaded correctly with certain dictionary phrases.

25535

HTML Stripper is not working after reloading the rules service.

25566

Message details remain in log database when message has been deleted, released, delayed.

25582

Rules log section within Web Message Administrator is showing "Rule log information not found".

25597

SurfControl E-mail Filter upgrade doesn’t upgrade the STEMConfig completely.

25643

PEM fails to process notifications due to apostrophe character in email address.

25661

Rolling back to a previous version of E=-mail Filter will leave e-mails in subfolders.

25663

No Help topic associated with Save Copy rules object.

25664

After rolling back from V5.5 to v5.2/5.0 SP3, the newly-created log database is still v5.5.

25666

Upgrading multiple servers to v5.5 adds multiple database records and corrupts the database.

25703

Rolling back E-mail Filter on multiple server installations cannot continue if services are not stopped on all servers.

25704

When upgrading to E-mail Filter v5.5, the Send service routes are not updated if the SQL Server 2005 computer has been renamed.

25811

E-mail Filter v5.5 Hot-Fix1a files to be included in the repackaged E-mail Filter v5.5.

25822

Update Readme for repackaged E-mail Filter v5.5.

25823

 

Description

Issue Number

Defects Fixed in 5.5 Hot-fix 2

Finding e-mails in queues based on the "To" field is now working.

25356

 

Description

Issue Number

Defects Fixed in 5.5 Hot-fix 3

Scheduled Queue Synchronization utility does not now change the time stamp of an isolated message.

8583

Purge now removes all data.

20722

Ability to retain the changes made to ‘Received’ dropdown box in Message Administrator.

25741

E-mails in the IN/OUT/QUEUES root folder are now correctly moved to subfolders during upgrade.

26238

Recovery mode for STEMLog & STEMFriendlyName is now set to ‘Simple’ on SQL Server.

26271

 

Known Issues

SurfControl E-mail Filter 5.5 for SMTP has the following known issues:

Description

Issue Number

Known Issues in 5.5

When using TLS, e-mails are delayed before they are sent to Qmail.

See Knowledge Base article 1796.

19391

The status of an e-mail that is deleted in QueueView is not updated in the Message Search list; it continues to be marked as ‘Pending Delivery’.

24920

Column inconsistencies in Message Administrator when selecting Logs > Audit Logs

You can select two ‘Server’ columns when inserting columns into the display. Also, if you insert all columns, select another log, and then select the Audit Log again, most columns are not displayed.

25169

Large number of BAD messages are created ignoring SUB folder scheme.

See Knowledge Base article 2025.

24028

SEF can't use existing SQL Express database files from previous installation.

See Knowledge Base article 2017.

24458

Messages that should be isolated are not showing in the Message Administrator.

See Knowledge Base article 2022.

25362

Data in STEMLog that has not been copied by SRC will never be purged.

See Knowledge Base article 2019.

25390

ASA Heuristics isolates the same number of spam e-mails if using Full Scan or Quick Scan

If there are multiple ASA Heuristics Rules defined and the scan mode (either Full Scan of message header and body, or Quick Scan of header only) differs between each instance, the Scan Mode of the last entry added in the list will be used for all ASA scans irrespective of the setting in the individual rules.

25456

For more information, please refer to the SurfControl Knowledge Base. Contact SurfControl Technical Support for further assistance.

Upgrade Considerations

You can either install a full version SurfControl E-mail Filter 5.5, or you can upgrade from the following versions:

·         SurfControl E-mail Filter 5.2/5.2.1

Note: Upgrade of the Administration Client installation is not supported. You will need to uninstall and re-install the Administration Client.

If you have upgraded to v5.5, you can uninstall this and ‘roll back’ to your previously installed version.

Please see the SurfControl E-mail Filter for SMTP v5.5 Starter Guide for upgrade, installation and rollback instructions.