Addressing E-Mail Spam for Small to Midsize Businesses
printer friendly format »
The following is a textual translation and summary of InfinIT’s podcast: Addressing E-Mail Spam for Small to Midsize Businesses
INTRODUCTION:
Welcome to the next edition of InfinIT Consulting’s podcast series. Our goal is to provide insight on the best IT solutions in the marketplace and address some of the most common business challenges small businesses to enterprise companies deal with.
Today we’ll be covering InfinIT’s new partnership with Barracuda Networks, a worldwide leader in e-mail and web security solutions. Barracuda Networks provides a large suite of products, including the Barracuda Spam Firewall, which we’ll be discussing today, as well as the Barracuda Web Filter, IM Firewall, Load Balance, Message Archiver, and Web Application Controller, which we will hopefully address in future podcasts.
For today’s podcast we will be focusing on their premier product, the Spam Firewall, and our customers who have implemented their solution.
We have three speakers with us today:
- George Gutierrez, Barracuda Networks Regional Sales Manager – West Coast
- John Tarn, Barracuda Networks Senior Sales Engineer
- Marcos Barrera, InfinIT Consulting Senior Sales Engineer who will be the moderator for today’s podcast
QUESTION/ANSWER SESSION:
Question:
Can you start us off today by telling us who Barracuda Networks is and how you differ from other vendors in your environment?
Answer:
[George Gutierrez]
To give a bit of an overview, Barracuda Networks has been around since 2002, we started shipping products in 2003 and since then we’ve established just over 50,000 customers worldwide. Our flagship product is the Barracuda Spam Firewall. We also have the Barracuda Spyware Firewall, which became the Barracuda Web Filter. Since then, we’ve introduced the Barracuda Instant Message Firewall, the Load Balance as well as the E-Mail Archiver, and have just recently acquired NetContinuum, which is now the Web Application Controller.
As far as what distinguishes us for our competitors is certainly our install base – we have over 50,000 customers worldwide. What that means for end users is that we have the most signature definitions out there. So any new spam and viruses that come out, Barracuda sees them first, so we can combat them first.
[John Tarn]
We also pride ourselves on customer feedback, taking feature enhancements very seriously. Our product development team pays great attention to bug fixes – new enhancements are put out once, twice, every three weeks. We have major releases at least once a quarter. That just makes us advance faster than anyone else out there.
[Marcos Barrera]
That’s a big piece as well in regards to how much of a sandbox do you have. How much raw data do you have to work with so that you can work with each problem and see these problems progress. When we’ve implemented these solutions in-house, the ease of use of the quarantine reports has always been a big piece for us and for our customers.
Question:
What things are important for business owners to consider before moving their company e-mail from a hosted POP service to in-house solution (ie. Exchange)?
Answer:
[George Gutierrez]
From a sales standpoint, for a lot of end users that don’t have a lot of protection, they are just inundated with spam, so of course that is going to affect productivity. So, the end result, the employer is not going to want their employees focusing their day on managing hundreds of e-mail messages, just deleting spam.
[John Tarn]
We’ve seen a lot of savings in network bandwidth especially. Just from the infrastructure standpoint, you have a mail server admin who doesn’t have to do RAM or CPU upgrades, they can wait six months to a few years if needed, just by reducing a lot of noise on that box by having us at the internal gateway. And, like you said, for a company migrating from a hosted solution to an internal solution, people take it for granted because a lot of hosted solutions right now, they give you spam protection without even telling you because they know they need to protect their internal systems as well.
[Marcos Barrera]
As a Microsoft shop, for us, Exchange is huge; but I used to also work in the Unix/Linux field. You have other products like Spam Assassin – but those are only as good as the person that knows how to configure them and how much time you have to configure them.
[John Tarn]
Exactly, there are other tools available out there. But with ours, you don’t have to spend hours a day tweaking the system to make sure no legitimate spam is getting caught, or managing hundreds of document libraries to make sure the systems are secure. That’s why the Barracuda is perfect – is does what it needs to do – it handles the e-mail.
Question:
What benefits do new customers have in trying out your product before purchasing?
Answer:
[George Gutierrez]
Our business model is based around our 30-day trial. So, we get our box directly into a customer’s infrastructure, let them test it out. They are going to know within the first 2- 3 days whether or not the box is going to work for them. As far as savings is concerned for the end user, the nice thing about the Barracuda is no per-user licensing fees. So, there is just a flat fee for the hardware and then there is simply an annual fee, which pays for the ongoing spam definitions, 24x7 tech-support and all firmware upgrades.
[John Tarn]
It definitely saves the admin a headache from having to go to their boss and saying ‘this is how much it’s going to cost’ and not knowing if it’s really going to solve their problem or not. We’re not afraid to get our product in front of the customer, in fact we encourage it. We know once you have it in there, you’re going to want to keep it. Compared to a lot of vendors, our appliance solution can be purchased often at a fraction of the cost of other solutions. And each box that we sell contributes to the success of our entire customer base. The more customers we have, the more spam we see and the more we can learn about preventing that spam from filtering in with user’s legitimate mail.
[Marcos Barrera]
Our customers definitely love the no per-user licensing fees. Licensing is expensive. You’re constantly getting dinged by a CAL here and a CAL there. The next thing you know is you have a licensing management nightmare. So, it was nice to be able to go to my customers and say – I have a device, it is what it is, it will hold this many users at this price point, and at the end of the day you won’t ever have to pay any individual user licensing fees. You pay to get your firmware updates and your support and that’s all. Then when I told them there was a 30-day trial on top of that, it was a no-brainer. Why wouldn’t you at least give it a try?
[George Gutierrez]
The time it takes to maintain the Barracuda is virtually nil. Out of the box, we have never been tested lower than a 94% catch rate by a third party. Our false positive rate is close to 0.01%. There is only about 1 out of every 10,000 good e-mails that gets classified as spam. The only real fine-tuning and tweaking that they’ll have to do to train the beige-in database, is probably about 15-20 minutes per day for about two weeks in the beginning to classify about 200 emails as spam and 200 emails as not spam, so if they want to increase their catch-rate by another 1 to 3% they can do that.
Question:
What is the optimal infrastructure to deploy the Barracuda Spam Firewall?
Answer:
[John Tarn]
That’s a good question. I often get systems administrators calling in prior to installing the Barracuda asking – what do I need to change, what do I need to put in place for this to work effectively. I suggest to put the Barracuda behind your firewall. It could sit out in the front of your network and give it a public IP, which people do and that’s not a problem, but I prefer it behind the firewall for extra security. It’s faster to have it point from the mail server into the Barracuda. For deployment, you simply plug it in, assign it an IP like you would any other advice and set up a domain – tell the Barracuda you’d like to accept mail from this domain or these domains, and then where do you want it to end up when we’re done cleaning it – and that’s it. You simply think of it in terms of how is mail flowing and that’s how you set the Barracuda up. The most time consuming piece I would say is actually putting it in your rack – to actually put the nuts and bolts together – that’s the longest piece.
[Marcos Barrera]
And it has a web management console so that people can manage it remotely, say if they have to VPN in if they have it stored in their colocation facility.
[John Tarn]
Exactly. Everything is web driven. The only time that you need to get to the console is to give it the initial IP to fit into your subnet and that’s it. Once you have an IP and subnet on, you go to the web interface, give it the DNS information and set up the domains you want to receive mail for – now the box is done and ready to go. You may have to fine-tune it a little bit, but it will catch approximately 94% of your spam. After the first week you should know, as each environment is different, how to adjust your spam scores to reach even higher percentages.
We have integrated OCR, so we do image spam recognition –we’re one of the first to do that. We do PDF scanning, there was a lot of PDF spam going out for a while. The updates help keep you on top of that as well. That’s what our customers are happy to pay for because we’re always staying on the edge and stopping all of the new spam attacks as well.
[Marcos Barrera]
That’s a big one for us. I used to work in a hosting environment and with our devices, it was a constant fight to figure out what was going to be the next beast. The problem was, we didn’t have a sandbox to test these problems in. We had multiple domains in a hosted environment that were coming into a server and it was being filtered. Unless our user base had enough fore-thought to send it to us, we would never know. Image spam was a huge one.
Question:
How does the Barracuda Spam Firewall integrate with Exchange Server?
Answer:
[John Tarn]
It integrates with Exchange the way it integrates with any other mail server. With Exchange, it’s even easier because the LDAP settings are all really well laid out in the help menus. That’s one of the reasons I love our product. We have a little ‘question mark’ next to every bold piece of configuration where you can see a popup help topic to explain the step you are working on. It integrates with the LDAP configuration settings – as long as it has read privileges – I usually just tell customers to create a separate user called ‘Barracuda’ in your Active Directory and assign it a password that’s never going to change that let’s us see who exists on the network. The Barracuda can help remove those processes that take a toll on your Exchange Server to handle mail and mail routing - especially for those users that are still running Exchange Server 2000 and haven’t upgraded to Exchange Server 2007 yet. Also, we utilize single-sign-on so people don’t have to remember a new set of credentials. They use their same domain credentials to log into the Barracuda and manage their own whitelists and blacklists and quarantine areas. So, yes, it has great integration with Exchange or any LDAP Server.
Question:
What size business works best with the Barracuda Spam Firewall?
Answer:
[George Gutierrez]
Our sweet spot is definitely working with small to medium sized businesses. We have customers as small as five users. As long as they’re running an e-mail server, they can use a Barracuda. We also have huge enterprise companies – University of Notre Dame, Colorado Rockies Baseball – these are just a few of our enterprise-class customers. But certainly, the SMB market by far is our best and most targeted market.
Question:
For enterprise customers, one of the most important features would be high-availability. What options do you have for that?
Answer:
[George Gutierrez]
The Barracuda Spam Firewall 400 and higher offers high availability.
[John Tarn]
It’s active – active configuration. So, if you have 2 devices for high availability you might as well have both scanning anyways, they’re breezing by mail real quick. That way, if one were to fail, the other one can pick up the slack – and load balancing is free. For ease of management, instead of managing two appliances, once you have them clustered, you can make configuration changes on any Barracuda and it will propagate to the other devices. Since they are both processing mail, you only have to run queries on one device, and it will query the other remotely and report back on what the message was and which device processed it – so it makes management really easy.
Question:
What are some of the other Barracuda product offerings?
Answer:
[George Gutierrez]
We have the Barracuda Web Filter – that’s going to keep users from going out to inappropriate websites or websites that contain spyware. That’s also going to block virus and spyware downloads as well. We have the Barracuda Instant Message Firewall, so for users that want to store and archive instant message traffic, they can do that using the IM Firewall. We have the Barracuda E-Mail Message Archiver, which allows users to archive sent and received e-mails outside of the company and also internally ranging from IT efficiency, so you don’t overload the e-mail server, legal holds, discovery requests, compliance needs such as Sarbanes Oxley (SOX) Compliance.
[John Tarn]
Even if your organization isn’t concerned with compliance efforts, it’s still a great tool to keep and to store mail. For example, if an employee lost an e-mail, it’s no longer the impossible task of looking through logs and logs of e-mails, with the Archiver it makes it really easy. You can use your Active Directory credentials to log in and search for the mail, re-deliver it, view the source, anything except deleting it.
CONCLUSION:
Thank you for joining us for today’s podcast. You can access our entire podcast series anytime on-demand through our website at www.infinITconsulting.com.
Be sure to join us for the next topics in our podcast series. We will be covering the hottest topics in the industry including virtualization, SAN storage solutions as well as key products including MOSS 2007, Exchange Server 2007, SQL Server and the newest Windows Server 2008 – Longhorn.
printer friendly format »
About InfinIT Consulting - Bay Area IT Consulting Service Provider
InfinIT Consulting, Inc. specializes in high end IT consulting, database management solutions and web optimization to empower businesses to embrace the real potential of IT.
InfinIT Consulting focuses on helping small, midsize and enterprise companies resolve their IT challenges and ultimately facilitate their daily business operations.
Their most demanded expertise includes IT managed services, IT integration for mergers and acquisitions, Sarbanes Oxley compliance, web portal design and implementation and IT infrastructure support and optimization. In addition, they offer a wide range of IT services including ERP project management, IT staff augmentation, data mining, database administration and web services including SEO, PPC campaign management, custom web design and web development.
Their customers are located across the nation with worldwide branches allowing them to cover areas from coast to coast, Asia and Europe.
For more information, please direct all press inquiries to:
Audrey Olsen
InfinIT Consulting
aolsen@infinITconsulting.com
408.439.9596
Kirsten Burkhardt
InfinIT Consulting
kburkhardt@infinITconsulting.com
408.205.8415
|