proofpoint gateway

pramod1
pramod1 used Ask the Experts™
on
regarding proof point gateway

Did we need Edge servers or not between Proofpoint and HUB?
-How to do recipient validation
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Jian An LimSolutions Architect
Top Expert 2016

Commented:
having Edge server or not is a on-premises requirement.
Some customer says all emails must terminate at DMZ, then EDGE is a must.
Usually, i don't see a reason if you can proove proofpoint gateway is a semi-controlled and act as your DMZ on email point of view.

to do recipient validation, proofpoint needs to have access to your ACtive directory via LDAPS to read your users.

you can look at the help file (it might not exactly the same but it definitely have something like this. talk to helpdesk if you have issues finding it)
http://support.proofpointessentials.com/index.php?/Knowledgebase/Article/View/42/11/active-directory-settings

Author

Commented:
can you highlight what other considerations needs to be addressed while setting up proofpoint gateway in DMZ
Solutions Architect
Top Expert 2016
Commented:
proofpoint gateway is in the cloud controlled by proofpoint.

so i said it "ACT" as DMZ, not it is saying it is "IN" DMZ.

the security concept is that everything entered from public to internal should be terminating in DMZ.
you have to argue proofpoint is not PUBLIC, it is semi-trusted because it is their job to make sure all connection is secure, clean and etc.

this way you argue you don't need to install an Exchange Edge server.


Depends on security officer, some of them accept you don't need an EDGe but some of them insist you need one.

I usually don't argue with security people but I always say everything we do come with a cost and whether it bring any benefit while proof point have done 90% of the job. In fact, not hosting any extra infrastructure on-premises is a bonus from my point of view.

I rest my case to security personnel and let them decide, but my recommendation is you don't need EDGE.

For proofpoint side, as long as you follow your on-boarding process, they covers everything. (unless you got a bad one)

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial