Multiple content filtering policies behavior for a Symantec Messaging Gateway appliance
search cancel

Multiple content filtering policies behavior for a Symantec Messaging Gateway appliance

book

Article ID: 152646

calendar_today

Updated On:

Products

Messaging Gateway

Issue/Introduction

When multiple content filtering policies are created to filter out content in a specific part of the message, such as "subject" or "envelope recipient" with an action to create a quarantine incident for each policy, the first content policy creates a quarantine incident message, but subsequent filtering policies create an informational incident, not a quarantine incident.

Cause

This is by design.  The idea behind this design is two-fold:

  1. A message should only be quarantine once, even if it triggers multiple content filtering policies.  Otherwise, it will have to be quarantined the first time due to the first policy, then released, and then quarantine again due to the second policy, and so on.
  2. An information incident is created for the subsequent or secondary policies to make sure it is known that those policies were triggered as well.

Resolution

There is no solution because this behavior is by design.  There are two choices: either re-write content filtering policies and choose which content you want to filter and what action you want to take or just use the information incident feature as a proof that the subsequent or secondary policies are being triggered.

 

These two places describe this behavior:

  • Administration Guide, the section "About multiple content filtering policies"
  • BMG Content Help (click on "Help" in the BMG web user interface, then click on "Search" tab, in the search box type "combining" and select "100. About Multiple content filtering policies".

Applies To

 Symantec Messaging Gateway versions 9.0 and higher.