<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: POP3, SMTP and IMAP setup in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pop3-smtp-and-imap-setup/m-p/117379#M45566</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For SMTP, choosing reset-both is a good idea because the firewall will send a 541 response to the sending SMTP server to prevent the message to be sent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For POP3 and IMAP, reset-both seems to cause the email clients to retry downloading the offending message eternally, so it probably interferes with the normal operation of the client. Still, that behavior is probably better than getting viruses inside your network (even if it's on personal computers).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Benjamin&lt;/P&gt;</description>
    <pubDate>Tue, 04 Oct 2016 03:53:49 GMT</pubDate>
    <dc:creator>BenjAudy.MTL</dc:creator>
    <dc:date>2016-10-04T03:53:49Z</dc:date>
    <item>
      <title>POP3, SMTP and IMAP setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pop3-smtp-and-imap-setup/m-p/117322#M45565</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our POP3, SMTP and IMAP is currently set to Default (Alert) in the AV profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have noticed malicious emails coming through and identified via Wildfire for staff using personal email addresses/computers using POP3 protocols? These personal computers are allowed on some of our remote sites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should POP3/SMTP and IMAP be set to Drop-reset for “Action” and “Wildfire” in the Anti-Virus security policy if it detects malicious file/link etc?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using Proofpoint to scan all our internal corporate email.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in Advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Antivirus.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5778i73C9B41F7B6660B4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Antivirus.png" alt="Antivirus.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2016 00:06:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pop3-smtp-and-imap-setup/m-p/117322#M45565</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2016-10-04T00:06:20Z</dc:date>
    </item>
    <item>
      <title>Re: POP3, SMTP and IMAP setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pop3-smtp-and-imap-setup/m-p/117379#M45566</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For SMTP, choosing reset-both is a good idea because the firewall will send a 541 response to the sending SMTP server to prevent the message to be sent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For POP3 and IMAP, reset-both seems to cause the email clients to retry downloading the offending message eternally, so it probably interferes with the normal operation of the client. Still, that behavior is probably better than getting viruses inside your network (even if it's on personal computers).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Benjamin&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2016 03:53:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pop3-smtp-and-imap-setup/m-p/117379#M45566</guid>
      <dc:creator>BenjAudy.MTL</dc:creator>
      <dc:date>2016-10-04T03:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: POP3, SMTP and IMAP setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pop3-smtp-and-imap-setup/m-p/117676#M45586</link>
      <description>&lt;P&gt;Thank you Benjamin&amp;nbsp;for your suggestion. Much appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2016 04:25:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pop3-smtp-and-imap-setup/m-p/117676#M45586</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2016-10-05T04:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: POP3, SMTP and IMAP setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pop3-smtp-and-imap-setup/m-p/119095#M45749</link>
      <description>I use reset-both for pop3 and imap, with no "known" problems. Blocks viruses like a charm... Even after SSL decrypt. This is gmail. THREAT ALERT : medium : 173.194.222.109 -&amp;gt; 192.168.4.164 Trojan-Downloader/VBS.agent.dpiwk(1210797) reset-both type: THREAT subtype: virus app: imap category: web-based-email contenttype: severity: medium direction: server-to-client sport: 993 dport: 49498 natsport: 993 natdport: 36862 flags: 0x81502000 proto: tcp action: reset-both</description>
      <pubDate>Thu, 13 Oct 2016 16:55:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pop3-smtp-and-imap-setup/m-p/119095#M45749</guid>
      <dc:creator>gtomte</dc:creator>
      <dc:date>2016-10-13T16:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: POP3, SMTP and IMAP setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pop3-smtp-and-imap-setup/m-p/149613#M49816</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;could you share in details what you mean by no "known" problems?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;after you set to "reset-both" for POP3/IMAP, did your&amp;nbsp;&lt;SPAN&gt;email clients keep retrying to download the offending message eternally?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;thanks for sharing.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 09:09:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pop3-smtp-and-imap-setup/m-p/149613#M49816</guid>
      <dc:creator>jintan</dc:creator>
      <dc:date>2017-03-27T09:09:17Z</dc:date>
    </item>
  </channel>
</rss>

