12.06.2016 Views

Sophos XG Firewall Administrator Guide v15.01.0

Sophos-XG-Firewall-Administrator-Guide

Sophos-XG-Firewall-Administrator-Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

| Protection | 149<br />

POP/S and IMAP/S Settings<br />

Don't Scan Emails Greater Than<br />

Specify maximum file size (in KB) for scanning. Files exceeding this size received through POP/IMAP will not<br />

be scanned.<br />

Default - 1024 KB<br />

Specify 0 to increase the default file size restriction to 10240 KB.<br />

Recipient Headers<br />

Specify Header value to detect recipient for POP3/IMAP.<br />

Default - Delivered-To, Received, X-RCPT-TO<br />

Figure 124: POP/S and IMAP/S Settings<br />

SMTP TLS Configuration<br />

TLS Certificate<br />

Select the CA for scanning SMTP traffic over SSL from the available options.<br />

Available Options<br />

DefaultSecurityAppliance_SSL_CAList of custom CAs if added. You can create the custom CA from Objects ><br />

Identity > Certificate Authority.<br />

Allow Invalid Certificate<br />

If enabled, SMTP over SSL connections will be allowed with an invalid certificate from the Email Server.<br />

Disable this option to reject such connections.<br />

Default - Enable<br />

Require TLS Negotiation with Host/Net<br />

Select the remote host (Email Server) or network from available options on whose connections TLS encryption<br />

is to be enforced. In other words, the Device will always initiate TLS-secured connections when Emails are to<br />

be sent to selected hosts/networks. If TLS is enforced but connection cannot be established, then Emails to that<br />

remote host/network are discarded.<br />

Require TLS Negotiation with Sender Domain<br />

Specify the Sender Domain(s) on whose Email connections TLS encryption is to be enforced.<br />

Sender Domain is the domain of the Email sender. Emails from the specified Sender Domain will be sent over<br />

TLS-encrypted connections only. If TLS is enforced but connection cannot be established, then Emails from that<br />

sender domain are discarded.<br />

Skip TLS Negotiation Hosts/Nets<br />

Select the remote host (Email Server) or network from available options on whose connections TLS encryption is<br />

to be skipped or bypassed. When configured, SMTP connections to selected hosts will be established in clear text<br />

and unencrypted.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!