Solved

TLS implementation question

Posted on 2014-12-31
8
369 Views
Last Modified: 2015-01-05
Hello Experts,

I have a client who wants to setup TLS to allow email between 2 companies. My client has an Exchange 2010 hybrid environment with office 365, and he wants to secure email communication with a lawyer firm

Please see request below


It is CompanyB's policy to "enforce" TLS. We will deliver email to domain(s) you specify only when we are able to establish a TLS connection to your server(s) which ensures that our email communications to any of your domains are sent securely.  We strongly recommend that you enforce your TLS connection(s) to all the Company's B domains for similar secure TLS email transmission of your data to any and all Aon recipients.

Company A:
Client has a Exchange hybrid 2010 environment with office 365, Symantec BrightMail spam gateway. internal email flow goes to Symantec Spam Gateway --> to Internet [Internet send connector[, they also have a Office 365 send connector and another internal Send connector for applications.

Company B; unknown , but I guess they have either Exchange 2010 or 2013

Can someone please summarize high level steps to setup TLS across companies? Please, consider the fact that we have Symantec Bright Mail servers spam gateways and office 365 hybrid environment

Can someone please attach a link, blog, technet, article with tons of screenshots step-by-step to deploy TLS across organizations?

Should we restart Exchange servers or spam gateways after deploying TLS?

Do we need some sort of certificates to allow emails tthrough TLS? IF SO, where this certificates should be deployed? at server level, at spam gateways? should we exchange certificates across companies?
if so , which certificate should be exchanged?

Your feedback is highly appreciated
0
Comment
Question by:Jerry Seinfield
  • 5
  • 2
8 Comments
 
LVL 8

Accepted Solution

by:
Jessie Gill, CISSP earned 500 total points
ID: 40526078
If your mail flows out through a smart host, like the Symantec gateway then configure TLS on that (I am presuming the spam gateway is an appliance or another box with your external IP attached to it for mail.  I.E if Company A sends email to Company B and it routes through a smart host to the Symantec gateway then configure TLS on Symantec mail gateway. because the Symantec bright mail gateway is the one opening the connection to the other mail server/gateway.  On the receiving end they will need to configure TLS and enforce for your domain, no need to exchange certificates, once the TLS session opens that will auto happen.

A lot of the time the most gateway appliances/software allow self signed certificates that work most of the time, other wise you will have to get a signed certificate and import that into your software/appliance.

What version of the symatenc messaging gateway do you have?

I found an instruction manual that has all the steps needed to setup TLS if you have what I think you have. www.symantec.com/business/support/.../smg_administration_guide.pdf
0
 
LVL 41

Expert Comment

by:Amit
ID: 40526611
0
 

Author Comment

by:Jerry Seinfield
ID: 40527831
The client has Symantec 10.0.2

With that being said, nothing has to be done from the exchange servers? All emails is routed to the spam gateway [inbound/outbound], my only concern is the Office 365 component

Is that guide applicable to version 10.0.2?
0
 

Author Comment

by:Jerry Seinfield
ID: 40527843
Amit, the symantec link is broken.

Can you please send the correct one, and respond my last question?
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Author Comment

by:Jerry Seinfield
ID: 40527920
Any updates?
0
 
LVL 41

Expert Comment

by:Amit
ID: 40527980
I gave you MS one. Not Symantec.
0
 

Author Comment

by:Jerry Seinfield
ID: 40527984
Ok, Jessie and all

Since all email is routed through Symantec spam gateway 10.0.2, and I need to implement TLS for a single company, can someone please summarize all steps to be performed from the Spam gateway [Symantec BrightMail 10.0.2] and from the exchange server

Like I mentioned earlier, the client has an Exchange 2010 Hybrid deployment with office 365, one internet send connector [all email goes to Symantec BrightMail host], and another send connector to Office 365

Will the TLS implementation be done at Symantec BrightMail and/or EXCHANGE SERVERS?

Can someone please attach official Symantec BrightMail guide 10.0.2 to implement TLS across 2 companies?
0
 

Author Comment

by:Jerry Seinfield
ID: 40528478
Anyone?
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article explains how to prepare an HTML email signature template file containing dynamic placeholders for users' Azure AD data. Furthermore, it explains how to use this file to remotely set up a department-wide email signature policy in Office …
This is my first article on Expert Exchange on the Manual Method of Exporting Office 365 Mailboxes to PST format by using the eDiscovery mechanism of Office. Hope you will enjoy the article.
This lesson covers basic error handling code in Microsoft Excel using VBA. This is the first lesson in a 3-part series that uses code to loop through an Excel spreadsheet in VBA and then fix errors, taking advantage of error handling code. This l…
This Experts Exchange lesson shows how to use VBA to loop through rows in Excel.  In order to sort, filter, and use database features, there needs to be a value in each column for every row. When data arrives with values missing, code to copy values…

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now