27.11.2012 Views

IronPort - advanced configuration guide

IronPort - advanced configuration guide

IronPort - advanced configuration guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 2 Configuring Routing and Delivery Features<br />

Controlling TLS<br />

OL-25137-01<br />

These values are explained in Table 2-8.<br />

Table 2-8 Values in the Destination Controls Table<br />

Field Description<br />

Concurrent<br />

Connections<br />

Maximum<br />

Messages Per<br />

Connection<br />

The maximum number of outbound connections that will be made by the Cisco<br />

<strong>IronPort</strong> appliance to a given host. (Note that the domain can include your internal<br />

groupware hosts.)<br />

The maximum number of messages allowed for a single outbound connection from the<br />

Cisco <strong>IronPort</strong> appliance to a given host before initiating a new connection.<br />

Recipients The maximum number of recipients allowed within the given period of time. “None”<br />

denotes that there is no recipient limit for the given domain.<br />

The minimum period of time — between 1 and 60 minutes — that the Cisco <strong>IronPort</strong><br />

appliance will count the number of recipients. Specifying a time period of “0” disables<br />

the feature.<br />

Note If you change the recipient limit, AsyncOS resets the counters for all messages<br />

already in the queue. The appliance delivers the messages based on the new<br />

recipient limit.<br />

Apply Limits Specifies whether the limit will be applied (enforces) to the entire domain or to each<br />

mail exchange IP address specified for that domain. (Many domains have multiple MX<br />

records.)<br />

This setting applies to connection, message, and recipient limits.<br />

Specifies whether the limit will be applied system-wide or for each Virtual Gateway<br />

address.<br />

Note If you have configured groups of IP addresses, but you have not configured<br />

virtual gateways, do not configure apply limits per each virtual gateway. This<br />

setting is intended only for systems configured to use virtual gateways. For<br />

information on configuring virtual gateways, see Using Virtual Gateway<br />

Technology, page 2-59.<br />

Note If limits are applied per each Virtual Gateway address, you can still effectively implement system-wide<br />

limits by setting the Virtual Gateway limit to the system-wide limit you want divided by the number of<br />

possible virtual gateways. For example, if you have four Virtual Gateway addresses configured, and you<br />

do not want to open more than 100 simultaneous connections to the domain yahoo.com, set the Virtual<br />

Gateway limit to 25 simultaneous connections.<br />

Note The delivernow command, when acting on all domains, resets all counters tracked in the destconfig<br />

command.<br />

You can also configure the TLS (Transport Layer Security) on a per-domain basis. If the “Required”<br />

setting is specified, a TLS connection will be negotiated from the Cisco <strong>IronPort</strong> appliance listener to<br />

MTA(s) for the domain. If the negotiation fails, no email will be sent through the connection. For more<br />

information, see Enabling TLS and Certificate Verification on Delivery, page 1-29.<br />

Cisco <strong>IronPort</strong> AsyncOS 7.6 for Email Advanced Configuration Guide<br />

2-47

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!