cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
820
Views
0
Helpful
1
Replies

ESA C60 Supports howmany doamins ?

bsrinu001
Level 1
Level 1

Hi Team,

We would like to know as of now we have Enforced TLS for 4200 domains on our C670 ESA, we will like to add more  600 domains shortly please let us know is its okay to add more domains, how the device will react. Thank you

1 Reply 1

Libin Varghese
Cisco Employee
Cisco Employee

Hi,

As a rough estimate, a single TLS connection requires the same amount of server resources as ten clear text conversations. The actual impact to your IronPort appliance will vary based on how many simultaneous TLS connections it must handle. To mitigate the performance impact, there is a limit to the number of TLS connections the IronPort appliance will allow. Currently the limit is 100 inbound and 100 outbound TLS connections.

If the connection limit is reached for outbound connections, AsyncOS will negotiate a clear text conversation with partners whose MTA (message transfer agent) allows it. The IronPort appliance will simply wait and try the connection again later.

If the connection limit is reached for inbound partners the IronPort appliance will issue a 421-'#4.4.5 Too many TLS sessions at this time' error and the partner will try again later.

In all instances where the connection limit is reached, an entry is written to the mail log indicating that the TLS connection limit has been exceeded.These log entries will include the following text: TLS connection limit exceeded.

Thank You!
Libin Varghese

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: