12-18-2014 02:23 PM
12-18-2014 02:53 PM
Some TLS stuff end up as entries in your mail logs (System Administration/Log Subscriptions, click on "mail_logs/" in the middle column.
You can also see stats under Monitor/TLS Connections.
To dig in you need to create a new log subscription, using the "SMTP conversation log" type, and then send some mail. (it gets verbose, so you'll want to remove it when you're done)
That should show you why you're having issues.
01-18-2015 06:06 PM
If this issue is still occurring, I would suggest the following throubleshooting steps to be sorted.
If inbound TLS traffic (IE: external servers connecting to IronPort for delivery of inbound emails) are coming as unencrypted.
Check the message tracking of some Incoming Emails, review which Sendergroup these connections are matching.
IE: UNKNOWNLIST, ALL, SUSPECTLIST etc.
Look at the respective mail-flow policies for these sendergroups.
GUI > Mail Policies > HAT overview > Here you can see which mail flow policy a sendergroup uses.
Click into the respective Mail Flow Policy.
Scroll down to Security Features
Ensure TLS is enabled to preferred here.
Submit, commit changes.
To ensure outgoing connections are TLS preferred encryption.
GUI > Mail Policies > Destination Controls
Default -> Set TLS to preferred.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide