OutboundTLS Required but RSA encyption if it can't
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-21-2014 10:34 AM
Hello, can we configure the Ironport to require all outbound connections to be TLS and if it cannot use TLS because the receiving host does not have it then it will send using the RSA encryption product inside of IronPort?
I can see where I can change the default destination control to require TLS but in that case it will simply not deliver it if TLS is not available. How can I require TLS but if it cannot do TLS then encrypt it?
Any help is appreciated.
Thanks
- Labels:
-
Email Security
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-21-2014 10:49 AM
There may be better ways (maybe a message filter??), but the easiest I see is to create an outgoing conent filter that catches all mail, and then setting the action to "Encrypt on Delivery". That action has the option to try TLS and use the encryption profile configured if TLS fails.
This option uses CRES, or your Ironport Encryption Appliance... its not the simplest solution...
