Advice and solutions for Kaspersky Security for Mail Server
32 topics in this forum
-
The materials provided on the Advice and Solutions (Forum Knowledgebase) part of the Forum result from the work of the Kaspersky Customer Support team and Forum community members. They are shared here for ease of use of Kaspersky products, deploying and configuring them. Please remember that using commands or recommendations from the articles without a clear understanding of their purpose may result in errors or system inoperability. Please note that some materials presented are not official, so technical support may decline to support a specific unsupported configuration in some instances. Please also ensure to use the official documentation, found in this link…
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. In most cases the issue is related to processing downloaded bases on the server drive. Databases are downloaded from our sites successfully, but the problem appears during compiling and copying the downloaded bases locally on the KSE server. Such behavior may be caused by the following: Not configured exclusions for KSE in Kaspersky Security for Windows Server or Kaspersky Endpoint Security. Other utilities (backup, for example), that may interfere with the file processing. Incorrect operation of the delete function on high-speed drives, for example, SSD drives.…
-
The OpenSSL library in the following product would be updated to the version 1.1.1y on October 3: Kaspersky Security Mail Gateway 2.0, 2.0 MR1, and 2.1; Kaspersky Web Traffic Security 6.1; and Kaspersky for Linux Mail Security 1.0. The updates will be delivered as part of the DB updates, you do not need to take an action to receive the updates. A reboot will be required for the changes to take effect. You will see the request to reboot in the web interface of the application If you have a product installed in a cluster mode, please kindly reboot nodes of the cluster one by one, ensuring that each node has booted up after the reboot, before rebooting the next one.…
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. Which TLS protocols are allowed by default By default, the following TLS protocols are allowed in Kaspersky Secure Mail Gateway 2.1 for SMTP data transfer: TLS security mode Protocols Attempt TLS Encryption Crypto-Policy = DEFAULT (by default) TLS 1.2, TLS 1.3 are allowed. TLS 1.0, TLS 1.1, SSL 2.0/3.0 protocols are not allowed. The possibility of unencrypted data transfer in SMTP s…
-
- 0 replies
- 3.5k views
- 1 follower
-
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. If anti-spam detects an e-mail as not definitely categorized as clean, it moves the e-mail to the "Temporary Quarantine" for 50 minutes to re-scan it with updated anti-spam databases. If upon after this 50 minutes' time the e-mail is not defined as spam, it is released automatically without any interaction with the user. The administrator has an option to manually release such e-mails from "Temporary Quarantine" before the 50 minute period ends. At the same time, the e-mail will remain in quarantine with the status "Released".
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. If multiple e-mails are selected in Security for Microsoft Office 365, they cannot be saved to disk. You can only save them one by one.
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. KSO365 is a cloud solution. It does not work in the cloud by itself but together with Microsoft Exchange Online (EOL) and its anti-spam and anti-virus protection. In more than 95% of cases, Microsoft Forefront (Ff) performs the spam and virus scans first, due to Microsoft's cloud architecture. Thus, if Ff has identified an email as spam, virus, phishing, etc., and has done with it any action (according to the settings) except “Skip”, we do not check this email and do nothing with it. We cannot change the verdicts given by other applications. If an email went to the user's box…
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. Scenario: Phishing links are detected but some emails are allowed through, even though the selected Action is Move to Junk Email folder . Solution: The original e-mail was already located in the Junk folder when our product started to scan it. The "Allow through" action was performed, in this case it means that we've added the phishing tag to the e-mail and left it in the Junk folder. Most likely this e-mail was detected by some third-party anti-malware/phishing solution (Microsoft anti-malware filters in EWS, for example) and was moved to Junk, then we've s…
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. When administrator attempts to establish a connection between KS4O365 workspace and their Exchange online organization by doing the following in the administration console: Office 365 connection → Exchange Online connection → Grant Access → passes the consent validation algorithm but in the end gets the Error processing the request error: This error is usually triggered by the browser settings on the client host that is performing the consent validation. Upon executing consent validation algorithm we get the access token from Microsoft. Then we redirect browser t…
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. Problem OAuth consent validation algorithm is the same for Exchange online, OneDrive and SharePoint online. Initial steps of consent validation algorithm are basically the following: A user is redirected to the Microsoft website, where the user agrees to provide necessary permissions for our Azure application. KS365 receives an OAuth callback confirming that the consent was received. But we do not trust this callback as it can be forged. The user is redirected to the Microsoft website to receive an access token that will be used for the validation of the u…
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. Why are emails detected by Microsoft Exchange Online not being detected by KS365? Because "first come, first served"? Yes. In more than 95% of cases, Microsoft Exchange anti-malware and anti-spam filters are processing all objects before KS4O365. That being said, all the detections performed by our application are actually detections of mail flow that has already been scanned by Microsoft filters if they are not disabled. If some email was already scanned and quarantined by Microsoft, then we do not receive it for scanning, as it was already done on the Microsoft side.
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. Access to the Microsoft quarantine is carried out immediately after the issuance of the consent. Additional quarantine access accounts, that were subject to the MFA restriction in the previous versions, are no longer required for quarantine access. The connection is carried out using the application to which the consent is issued.
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. Is there any capacity limit of mails in the Quarantine zone? If any, can we modify it? Unfortunately, there is no possibility to customize this setting per user, it is hardcoded in the product (30 days for objects in the backup and 92 days for statistics). Is there any limit on the number of emails that can be stored in the Quarantine? On the KS4O365 side, there isn't a limit to the number of emails that can be saved in the backup. KS4O365 stores only metadata information about the emails in the backup, which is quite small in comparison to the email itself. …
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. Description When installing or upgrading KSE, you may encounter various issues when installing or starting our service. If a user has repeated the installation many times and changed many settings manually, we recommend to remove KSE completely using the instructions below. Cause There are files that remain in the system from a previous KSE installation, so a new installation cannot be successful. Solution Delete the remaining KSE files from the Exchange server manually. Follow the instructions below. 1. Delete all the remaining KSE agents. To do so, start E…
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. The table below contains the criteria for Kaspersky Security for Microsoft Exchange Servers 9.0 MR6 settings health check. Using the settings as specified in the table ensures meeting the recommended security level of the system. № Parameters (settings) to check Check criterion Expected result …
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. In order to send messages from backup with headings without saving them, please navigate to:
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. Version: Kaspersky Security for Exchange 9.5.10000.64, 9.6.96 Scenario In Kaspersky Security 9.0 for Microsoft Exchange Servers there's the following error event: "AM Error Kernel: The Anti-Virus (Anti-Spam) module has been switched to limited scan mode for next 30 minutes. Some objects may be skipped without being scanned." The same error message appears on the KSE console: Solution Sometimes Exchange tries to give KSE more emails to check than KSE is able to to check. In order to prevent delays in mail delivery, the anti-virus or/and anti-spam engine s…
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. Completely exclude the KSE folder with all its subfolders and all KSE processes from the scan scope: Kavscmesrv.exe Antiphishing.OutprocScanner.exe Antispam.OutprocScanner.exe Antivirus.OutprocScanner.exe Kse.Ksn.exe Kse.Licensing.exe Kse.Updater.exe
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. Description When upgrading KSE, the following error can occur: The CheckFilesLockActionStep action resulted in an error: File C:\Program Files(x86)\Kaspersky Lab\Kaspersky Security for Microsoft Exchange Servers\NativeResources.dll is locked. The installation log contains the following: Exception: System.ApplicationException: File C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security for Microsoft Exchange Servers\NativeResources.dll is locked. Solution This error means that somewhere (locally or remotely) Event Viewer is open and viewing events from th…
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. Scenario Kaspersky Security for Exchange installation failed with the following error: "Failed to grant rights to run under a different name (impersonation) for Kse Watchdog Service". Solution If you get the error message about impersonation, execute the following command in PowerShell: Add-PsSnapin Microsoft.Exchange.Management.PowerShell.E2010 Remove-ManagementRoleAssignment KSE_IMPERSONATION -Confirm:$False Press the Retry button.
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. Version: KSE for Microsoft Exchange Server versions 9.5.10000.64, 9.6.96. Scenario: We have established a workaround to a problem with invalid SQL server parameters during its installation. An error about invalid SQL server parameters occurred during the installation: "The server was not found or was not accessible. Verify that the instance name is correct, and that SQL Server is configured to allow remote connections. Error 26 - Error Locating Server/Instance Specified". We have found the following information from installation log: …
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. Problem Description, Symptoms & Impact Sometimes an error might occur when installing KSE: KseCheckServicePortIsFreeActionStep has completed with an error: Service network port 13100 is occupied by another application… Diagnostics Screenshot or KSEInfoCollector. Make sure that port 13100 is open and not used by any application, and repeat the installation. This can be done using the command below. You will see a chart with a process ID (PID column) next to the address and port: netstat -aon | findstr 13100 You can then find this pr…
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. Scenario In certain cases one may need to move an SQL database that stores KSE operational data to another SQL server/instance. The following procedure can be used to achieve that: Step-by-step guide Change the startup type of KSE services to Manual. Stop the KSE services which use this database (may be located on several hosts in case of DAG, for example). Create a backup of the KSE database using MS SQL tools. Restore the database on a new SQL server/instance using MS SQL tools. Assign the required rights for this database according t…
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. Administrator receives the notification about outdated anti-spam (AS) and/or anti-virus (AV) bases because a large time interval for updating AS and/or AV databases is set (every 5 hours or more for AS and every 24 hours or more for AV). Anti-spam and anti-virus bases should be updated much more often. Accordingly, Kaspersky Security Center should also update anti-spam and anti-virus bases more frequently. The best way is to update anti-spam bases directly via Internet from Kaspersky Update servers every 5 minutes. Anti-virus bases should be updated every 1 hour. If it is not…
-
Advice and Solutions (Forum Knowledgebase) Disclaimer. Read before using materials. To install the solution in the silent mode, run the command line with administrator rights and execute the following command: msiexec /i "<PATH_TO_MSI>" /qn ADDLOCAL="<FEATURES>" SQL_SERVER_NAME="<SQL_SERVER_NAME>" BACKUP_DATABASE_NAME="<DATABASE_NAME>" SQL_ACCOUNT_DLG_USER_TYPE="UserAccount" SQL_ACCOUNT_DLG_USER="<UserName>" SQL_ACCOUNT_DLG_PASSWORD="<Password>" SERVICE_ACCOUNT_DLG_USER_TYPE="UserAccount" SERVICE_ACCOUNT_DLG_USER="<UserName>" SERVICE_ACCOUNT_DLG_PASSWORD="<Password>" INSTALLDIR="<INSTALLATION_DIRECTORY>" DAT…