27.11.2012 Views

IronPort - Configuration Guide - AsyncOS 7.6.1

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

3-4<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email <strong>Configuration</strong> <strong>Guide</strong><br />

Chapter 3 Setup and Installation<br />

See “Using Virtual Gateway Technology” in the Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> for Email Advanced<br />

<strong>Configuration</strong> <strong>Guide</strong> and Appendix B, “Assigning Network and IP Addresses” for more information<br />

about assigning multiple IP addresses to the available interfaces.<br />

Note The Cisco <strong>IronPort</strong> X1000/1050/1060/1070, C60/600/650/660/670, and C30/300/350/360/370 Email<br />

Security appliances have three available Ethernet interfaces by default. The Cisco <strong>IronPort</strong><br />

C10/100/150/160 Email Security appliances have two available Ethernet interfaces.<br />

Advanced <strong>Configuration</strong>s<br />

Firewall Settings (NAT, Ports)<br />

In addition to this configurations shown in Figure 3-2 and Figure 3-3, you can also configure:<br />

Multiple Cisco <strong>IronPort</strong> appliances using the Centralized Management feature<br />

Redundancy at the network interface card level by “teaming” two of the Ethernet interfaces on Cisco<br />

<strong>IronPort</strong> appliances using the NIC Pairing feature.<br />

Both of these features are discussed in the Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> for Email Advanced <strong>Configuration</strong><br />

<strong>Guide</strong>.<br />

Depending on your network configuration, your firewall may need to be configured to allow access on<br />

the following ports.<br />

SMTP and DNS services must have access to the Internet. For other system functions, the following<br />

services may be required:<br />

Table 3-1 Firewall Ports<br />

SMTP: port 25<br />

DNS: port 53<br />

HTTP: port 80<br />

HTTPS: port 443<br />

SSH: port 22<br />

Telnet: port 23<br />

Appendix C, “Firewall Information” contains all information about the possible ports that may need to<br />

be opened for proper operation of the Cisco <strong>IronPort</strong> appliance. For example, ports in the firewall may<br />

need to be opened for connections:<br />

from the external clients (MTAs) to the Cisco <strong>IronPort</strong> appliance<br />

to and from groupware servers<br />

to the Internet root DNS servers or internal DNS servers<br />

to the Cisco <strong>IronPort</strong> downloads servers for McAfee and Sophos Anti-Virus updates, Outbreak<br />

Filters rules, and updates to <strong>AsyncOS</strong><br />

to the NTP servers<br />

to LDAP servers<br />

LDAP: port 389 or 3268<br />

NTP: port 123<br />

LDAP over SSL: port 636<br />

LDAP with SSL for Global Catalog queries: port 3269<br />

FTP: port 21, data port TCP 1024 and higher<br />

Cisco <strong>IronPort</strong> Spam Quarantine: port 6025<br />

OL-25136-01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!