05.08.2013 Views

InterScanTM Messaging Security Virtual Appliance - Online Help ...

InterScanTM Messaging Security Virtual Appliance - Online Help ...

InterScanTM Messaging Security Virtual Appliance - Online Help ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring Transport Layer <strong>Security</strong> Settings<br />

This policy is set to limit communication with IMSVA through a TLS connection to:<br />

• a specific IP address ()<br />

• a trusted certificate<br />

• a cypher with at least a medium security level<br />

• a connection protocol that is only TLSv1<br />

Configuring Downstream TLS Settings<br />

Configure main.cf and smtp_tls_policy to apply TLS settings to specific<br />

downstream connections. For example:<br />

• Modify main.cf:<br />

smtp_tls_security_level=none<br />

smtp_tls_policy_maps=<br />

hash:/opt/trend/imss/postfix/etc/postfix/smtp_tls_policy<br />

• Modify smtp_tls_policy:<br />

[]:25 may<br />

example.com encrypt<br />

In the example above, servers not listed in the smtp_tls_policy will communicate<br />

with the Postfix client without TLS.<br />

The security level can be changed from may to encrypt or verify as required.<br />

For more information on security parameters in the downstream site-specific TLS<br />

settings, visit the following site:<br />

http://www.postfix.org/TLS_README.html#client_tls_policy<br />

Creating and Deploying Certificates in IMSVA<br />

This section provides you with an introduction on how to create and deploy certificates in<br />

IMSVA for Transport Layer <strong>Security</strong> (TLS) environments.<br />

11-13

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!