Messaging Gateway

 View Only

Expand all | Collapse all

IP address of connection

  • 1.  IP address of connection

    Posted Jan 08, 2025 07:30 AM

    Hi,

    Is there any way to see the IP address of connection which is being dropped due to Bad reputation?



  • 2.  RE: IP address of connection

    Posted Jan 08, 2025 08:11 AM
    Unclassified | Non classifi?

    Yes. The Audit logs.




  • 3.  RE: IP address of connection

    Posted Jan 08, 2025 08:43 AM

    I think I didn't describe the problem properly:

    in a specific time frame, we have huge number of Bad IP Reputation blocks. I want to see who they are. Message Audit Logs can only search for a Connection IP if you know it.




  • 4.  RE: IP address of connection

    Posted Jan 08, 2025 08:45 AM
    Unclassified | Non classifié

    Correct. It’s in the audit logs.




  • 5.  RE: IP address of connection

    Posted Jan 08, 2025 09:39 AM
    Search by Connection IP and put in a single dot in the search criteria field. Every IP has a dot in it. So the search will find all the connections.

    You can also add optional search criteria based on Verdict, like “The sender’s IP address is in the Symantec Global Bad Senders List” or “The connection was blocked by Connection Classification”.




  • 6.  RE: IP address of connection

    Posted Jan 08, 2025 10:13 AM
    Unclassified | Non classifié

    That “may” work. Hmm🤔




  • 7.  RE: IP address of connection

    Posted Jan 08, 2025 10:31 AM
    It worked for me a bunch of times.

    The search like this may produce too many results, depending on how busy and how “popular” your SMG is. Ours gets bombarded with thousands of connections per minute. So in our case when we do searches like this, we have to really narrow down the time range of the search.




  • 8.  RE: IP address of connection

    Posted Jan 08, 2025 10:33 AM
    Unclassified | Non classifié

    The issue with smg u can’t get more than a 1000 results per scanner with is so ****.




  • 9.  RE: IP address of connection

    Posted Jan 08, 2025 10:58 AM
    Exactly. Although somewhere in the settings you can configure SMG to return more than 1000 audit log search results per scanner, with a warning that it could negatively impact performance.




  • 10.  RE: IP address of connection

    Posted Jan 08, 2025 12:06 PM
    Nope, 1000 is the max.




  • 11.  RE: IP address of connection

    Broadcom Employee
    Posted Jan 08, 2025 03:55 PM

    There is also the REST API to query MAL that was introduced.  It doesn't have any restriction on number of responses.




  • 12.  RE: IP address of connection

    Posted Jan 08, 2025 04:31 PM
    Is there a command line for this REST API ?




  • 13.  RE: IP address of connection

    Posted Jan 08, 2025 04:33 PM
    Unclassified | Non classifié

    Not that I have tried. I want like 10000 but Symantec won’t make it in the gui. Very yuky




  • 14.  RE: IP address of connection

    Broadcom Employee
    Posted Jan 09, 2025 11:44 AM

    One of the API endpoints exposes an interface to query the Message Audit Log (MAL), the CLI (roughly equivalent) command would be the "malquery" command.  

    Also want to call out that the override to the 1000 result limit you mentioned is available via the "-m" or "--max" options of the malquery CLI command.  

    Details about the REST API endpoints, is available in the product documentation at:

    https://techdocs.broadcom.com/us/en/symantec-security-software/email-security/messaging-gateway/10-9-0/Administration---Settings/smg-rest-api.html




  • 15.  RE: IP address of connection

    Posted Jan 09, 2025 11:48 AM
    Yah, the UI is still 1000 max result. That is very bad. boooooooooooooo