Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Enabling TLS for a company that uses Exchange 2010 hybrid environment O365 and spam gateway[Symantec BrightMail 10.0.2] to route inbound outbound emails

Posted on 2015-01-03
9
Medium Priority
?
651 Views
Last Modified: 2015-01-05
Hi Experts,

I opened another blog with same question, but it seems like nobody is able to provide a full feedback in all steps required from exchange server and from Symantec Spam Gateway to enable TLS for a single domain.

http://www.experts-exchange.com/Networking/Protocols/Email/Q_25118415.html

As per link above, I have almost same identical infrastructure. All inbound/outbound email goes to Symantec BrightMail spam gateway[through send connector] and we also have another send connector to Office 365.

Should I create send connectors in the exchange server to use TLS for a single domain?

Should I setup a new domain in the spam gateway to force TLS for a single company?

Can someone please indicate all steps required from both exchange and Symantec BrightMail 10.0.2?

I am a little confused here with the Symantec appliance and O365. I do not want to enable TLS for the entire organization, only for emails sent to a specific partner

Please see links below, and let me know your thought

http://www.symantec.com/business/support/index?page=content&id=TECH96523
http://www.symantec.com/connect/forums/ok-guys-how-do-you-enforce-tls-brightmail
http://www.symantec.com/business/support/index?page=content&id=HOWTO58876
http://www.symantec.com/connect/forums/tls-encrypted-smtp-connection
http://www.symantec.com/business/support/index?page=content&id=TECH91365
http://www.symantec.com/business/support/index?page=content&id=TECH96523
0
Comment
Question by:Jerry Seinfield
  • 5
  • 4
9 Comments
 
LVL 44

Expert Comment

by:Vasil Michev (MVP)
ID: 40529534
If all inbound/outbound mails are hitting the spam appliance first, and you want to only enforce TLS for specific domain, you should do it on the appliance level. Nothing should be needed on O365 side.

For the sake of completeness, you can enforce TLS in O365 using these two methods:

 - use an inbound/outbound connector: http://technet.microsoft.com/en-us/library/dn751021(v=exchg.150).aspx
 - use a simple transport rule with the "recipient domain is" condition and the "require TLS" action

The first method is generally more secure, as you can require the other side to have a valid publicly trusted certificate with the said domain added as SAN/CN, but it's a bit more difficult to configure. The second method is easier to configure, gives you a lot of flexibility when combined with out actions/exceptions/conditions, but will work against any certificate (even self-signed).
0
 

Author Comment

by:Jerry Seinfield
ID: 40529721
Vasil, are you saying that I need to perform a transport rule on the Symantec BrightMail spam gateway appliance?

Did you read all symantec links posted above?

If everything has to be done on the spam gateway, can you please write down all steps?
0
 

Author Comment

by:Jerry Seinfield
ID: 40529805
Anyone?
0
WatchGuard Case Study: Museum of Flight

“With limited money and limited staffing, we didn’t have a lot of choices in terms of what we could do to bring efficiency. WatchGuard played a central part in changing that.” To provide strong, secure Wi-Fi access within the museum, Hunter chose to deploy WatchGuard’s AP120 APs.

 
LVL 44

Expert Comment

by:Vasil Michev (MVP)
ID: 40529966
Sorry, I'm not an expert on BrightMail, but the first article you linked seems to contain the instructions you need.
0
 

Author Comment

by:Jerry Seinfield
ID: 40530308
Thanks Vasil,

With that being said, everything should be done on the Symantec appliance and the instructions would be below?


TLS for delivery to specific domains:
You may enable TLS for delivery of mail on a per-domain basis.
Select the Protocols tab.
Select Domains under the SMTP sidebar on the left hand side of the page.
Either select the Add button to add a new domain or select a domain and click the Edit button to change an existing domain.
Select the Delivery tab.
In the TLS Encryption box, Check the box for Optional delivery encryption
Select either Attempt TLS encryption or one of the two Require TLS options. Note: If either of the Require TLS encryption options are chosen and the remote mail system does not support TLS, the messages will bounce for that system.
Select Save to commit the changes.

What about the certificates? Should I use a public CA? can you please elaborate this? Where the certificate should be generated? Would it be generated on the Symantec Appliance or from a external or internal PKI CA?

Does anybody from Antivirus team has any thoughts?
0
 
LVL 44

Expert Comment

by:Vasil Michev (MVP)
ID: 40530374
Self signed will do, but the most secure way is to use a valid publicly trusted certificate with the domain name added as SAN/CN.
0
 

Author Comment

by:Jerry Seinfield
ID: 40530650
Vasil, so basically you are saying that the public certificate should be a SSL SAN certificate with the domain name of both companies?

Should we exchange the cert across companies?
If so, I guess the cert should be imported onto the Symantec Appliance Gateway?
0
 

Author Comment

by:Jerry Seinfield
ID: 40530752
Can someone else from the AV team provide with your thoughts?
0
 
LVL 44

Accepted Solution

by:
Vasil Michev (MVP) earned 1500 total points
ID: 40531050
Um, no. It's preferable to have publicly trusted one, but self signed will do as well. If using publicly trusted one, you can restrict the TLS configuration to check specifically for that domain name present in the SAN/CN.
0

Featured Post

Lessons on Wi-Fi & Recommendations on KRACK

Simplicity and security can be a difficult  balance for any business to tackle. Join us on December 6th for a look at your company's biggest security gap. We will also address the most recent attack, "KRACK" and provide recommendations on how to secure your Wi-Fi network today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

With its various features, Office 365 can not only help you with your day-to-day business tasks, it can also do wonders for your marketing campaign.
How to effectively resolve the number one email related issue received by helpdesks.
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…
Look below the covers at a subform control , and the form that is inside it. Explore properties and see how easy it is to aggregate, get statistics, and synchronize results for your data. A Microsoft Access subform is used to show relevant calcul…

916 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question