05-03-2021 10:05 AM
I'm trying to setup email encryption and we use Barracuda Email Security Gateway. It appears outbound encrypted emails are not going through because of ESMTP on Firepower. Is there a workaround instead of disabling it completely?
06-02-2021 01:48 PM
Just wanted to throw this back to the top. If there's no workaround, can someone please explain to me the consequences from disabling ESMTP? Is it worth disabling ESMTP for email encryption?
06-07-2021 10:50 AM
Are you sure it's the esmtp ALG that's giving you problems? I recently had a customer with Barracuda and Firepower who was having problems. It turned out their on-premise server wasn't setup to use TLS 1.2 and Barracuda discontinued support of TLS 1.0 several months back. Changing the TLS settings on the server side fixed their issue.
06-07-2021 12:32 PM
Yes. Barracuda support was contacted and one of their engineers stated that it's the esmtp that's preventing their email encryption plugin from working. They verified TLS 1.2 is setup and working as it should.
06-07-2021 09:05 AM
By default on my device I didn't see esmtp being enabled.
You can check on yours by running command by doing SSH to FTD
> show running-config policy-map
You can disable/enable esmtp using the following command:
> configure inspection esmtp disable Building configuration... Cryptochecksum: b5e5234b 216d8639 a2eee0be ee671d42 5745 bytes copied in 0.90 secs [OK] >
you can read more about it here as the concept remains same in both ASA and FTD.
Regards,
Chakshu
Do rate helpful posts.
06-07-2021 12:33 PM
Yes we checked ours when this was a known issue and ours is enabled.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide