Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Email Security Quick-links: ESA Product Support | SMA Product Support | Email Submission and Tracking Portal | Cisco SecurityHub
Current General Deployment (GD) Releases:
ESA: 11.0.0-264 WSA: 10.5.1-296 SMA: 11.0.0-115 Email Plug-in (Reporting): 1.0.1-048 Email Plug-in (Encryption): 1.0.0-036

New Member

Cisco Ironport Email Security inline with Microsoft Forefont

Hi,

We are going to deploy Cisco C370 Email security appliance as new email relay in our DMZ. Currently Microsoft Forefont is already doing the same functionality and new Ironport email security appliance will be added as 1st layer of email security. 

I would like to know what are the changes that we should consider in this deployment in order to forward mail to Forefont, is there any specific configuration on both products and what is the best method of deployment etc.

Also I would appreciate if there is any Cisco/Microsoft documentation available for such deployment senario.

thanks in advance.

 

Everyone's tags (1)
3 REPLIES

Hello pemasirid,as far as I

Hello pemasirid,

as far as I can see from your description is that you add the ESA C370 as an additional gateway, so I would say there is little you need to change in your current network design. As this is all about SMTP getting forwarded, you basically just need to take care of the following things:

 

On Forefront: Allow injections from the ESA(s) and forward all outbound messages to the ESA

On the ESA(s): Insert the Forefront IPs into the RELAYLIST of the private listener to allow outbound messages. Also set up an SMTP route to forward inbound messages to the Forefront server.

Also change public DNS to point to the public IPs of the ESAs, in case they are different from what you have used before

 

A good starting point for deploying would be the Quickstart Guide for C370, that you can find in the support section for email security on Cisco.com. Also, the user guide, which is also available on the GUI of every email appliance (GUI: Help and Support -> Online Help).

 

Hope that helps,

Andreas

New Member

Dear Andreas,Many thanks for

Dear Andreas,

Many thanks for your response and really appreciated.

Due to some rack issue the implementation part of ESA 370 is getting delay and I will keep you posted, if I need further help/advise from you.

Once again thanks for your response.

New Member

Dear Andreas,Many thanks for

please see my response below..

107
Views
0
Helpful
3
Replies