Kaspersky Anti Targeted Attack (KATA) Platform

Configuring integration with a mail server via SMTP

8 November 2023

ID 247534

If you are using the distributed solution and multitenancy mode, use the web interface of the PCN or SCN server for which you want to configure parameters.

To configure integration with a mail server over SMTP:

  1. Select the Sensor servers section in the window of the application web interface.

    The Server list table will be displayed.

  2. Select the Sensor component for which you want to configure integration with the mail server via SMTP.

    This opens the Sensor component settings page.

  3. Select the SMTP integration section.
  4. In the State field, set the toggle switch to Enabled.
  5. In the Destination domains field, specify the name of the mail domain or subdomain. The application will scan email messages sent to mailboxes of the specified domains.

    To disable a domain or subdomain, enclose it in the !domain.tld form.

    If you leave the mail domain name blank, the application will receive messages sent to any email address.

  6. In the Clients field, specify the IP addresses of hosts and/or masks of subnets (in CIDR notation) with which the application is allowed to interact over the SMTP protocol.

    To disable a host or subnet, enclose the address in the !host form.

    If you leave this field blank, the application will receive the following messages:

    • From any email addresses if you specified email domains in the Destination domains field.
    • From a mail server in the same subnet as the server with the Sensor component if no domain is indicated in the Destination domains field.
  7. If you want the application to receive messages of any size, in the Message size limit settings group, select the Unlimited check box.
  8. If you want to set a maximum allowed size of incoming messages:
    1. Clear the Unlimited check box.
    2. In the field under the check box, enter the maximum allowed size of a message.
    3. In the drop-down list to the right of the field, select the unit of measurement.
  9. Click Apply.

Integration with a mail server via SMTP will be configured. The application will scan email messages received over the SMTP protocol according to the defined settings.

If you have deployed the Central Node and Sensor components as a cluster, you can configure fault-tolerant integration with the mail server.

To configure fault-tolerant integration with the mail server:

  1. Configure Round Robin on the DNS server for the domain name corresponding to the Central Node cluster.
  2. Specify this domain name in the mail server settings.

Integration with the mail server will be configured based on the domain name. The mail server will communicate with a random server in the cluster. If this server fails, the mail server will communicate with another healthy server in the cluster.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.