?
Solved

Exchange and SMTP over TLS

Posted on 2014-03-02
7
Medium Priority
?
501 Views
Last Modified: 2014-03-02
I am looking to setup SMTP over TLS for several clients who all are running Exchange. I am not looking to FORCE TLS at this time but would like:

Exchange to first attempt an SMTP over TLS connection FIRST. If this cannot be negotiated, then fail back to regular SMTP.

My initial searches did not return many good guides on this.

All clients are running either Exchange 2010 or 2013.
0
Comment
Question by:Schuyler Dorsey
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
7 Comments
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 1000 total points
ID: 39898552
The reason you found no guides was because there is nothing you need to do.

Since Exchange 2007, Exchange uses opportunist TLS by default - if TLS can be used then it will use it, only falling back to plain SMTP.

Simon.
0
 
LVL 10

Author Comment

by:Schuyler Dorsey
ID: 39898560
So there is ZERO config required to do this? And thank you!
0
 
LVL 16

Assisted Solution

by:Michael Ortega
Michael Ortega earned 1000 total points
ID: 39898592
Correcto. Exchange 2007 forward is set to use TLS opportunistically. The great thing about it is that if you are emailing people that are also using Exchange 2007 or newer all your messages are sent and received by default over a TLS connection.

If you do want to start forcing TLS you can create a 2nd send connector and only check TLS in the properties. Then scope the connector for which recipient domains you want to force TLS to.

MO
0
Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 
LVL 10

Author Comment

by:Schuyler Dorsey
ID: 39898596
Also.. does Exchange use START TLS as oppose to SMTPS? If so, does it do this still over port 25? Just trying to make sure I have the correct inbound/outbound ports on the firewall available.

I see that 465 is used for the older SMTPS.
0
 
LVL 16

Expert Comment

by:Michael Ortega
ID: 39898598
Yes, over port 25 and uses STARTTLS.

MO
0
 
LVL 16

Expert Comment

by:Michael Ortega
ID: 39898602
Correction on my previous note above. I was mixing up my receive and send connector configurations. Your receive connector would need to be set to only allow TLS authentication and the senders IP(s) to be set in the network settings of the receive connector.

MO
0
 
LVL 16

Expert Comment

by:Michael Ortega
ID: 39898605
The receiving side would essentially need to do the same thing on their end and that would be how you enforce TLS on both sides.

We use 3rd party filters on our systems that do the enforcement for us, so that's where the mixup above came with the send connector. We simply scope our send connector to relay through the filter which then performs the enforcement of TLS.

MO
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

MS Outlook is a world-class email client application that is mainly used for e-communication globally.  In this article, we will discuss the basic idea about MS Outlook, its advanced features, and types of MS Outlook File formats.
Find out what you should include to make the best professional email signature for your organization.
how to add IIS SMTP to handle application/Scanner relays into office 365.
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question