cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1486
Views
0
Helpful
5
Replies

Disabling ESMTP - Firepower

fuy5
Level 1
Level 1

I'm trying to setup email encryption and we use Barracuda Email Security Gateway. It appears outbound encrypted emails are not going through because of ESMTP on Firepower. Is there a workaround instead of disabling it completely?

5 Replies 5

fuy5
Level 1
Level 1

Just wanted to throw this back to the top. If there's no workaround, can someone please explain to me the consequences from disabling ESMTP? Is it worth disabling ESMTP for email encryption? 

Are you sure it's the esmtp ALG that's giving you problems? I recently had a customer with Barracuda and Firepower who was having problems. It turned out their on-premise server wasn't setup to use TLS 1.2 and Barracuda discontinued support of TLS 1.0 several months back. Changing the TLS settings on the server side fixed their issue.

Yes. Barracuda support was contacted and one of their engineers stated that it's the esmtp that's preventing their email encryption plugin from working. They verified TLS 1.2 is setup and working as it should. 

Chakshu Piplani
Cisco Employee
Cisco Employee

By default on my device I didn't see esmtp being enabled.

You can check on yours by running command by doing SSH to FTD

 

> show running-config policy-map 

You can disable/enable esmtp using the following command:

> configure inspection esmtp disable 
Building configuration...
Cryptochecksum: b5e5234b 216d8639 a2eee0be ee671d42 

5745 bytes copied in 0.90 secs
[OK]
> 

you can read more about it here as the concept remains same in both ASA and FTD.

 

Regards,

Chakshu

 

Do rate helpful posts.

Yes we checked ours when this was a known issue and ours is enabled. 

Review Cisco Networking for a $25 gift card