Data Loss Prevention

 View Only
  • 1.  Symantec DLP Email Prevent integration with MTA

    Posted Aug 22, 2016 08:40 AM

    Hello Everyone,

    I am facing issues while integration between Email Prevent v14 and Clearswift Secure Email Gateway v3.8. We currently have DLP v11.6 running and it is  integrated with Clearswift MTA on Reflect mode for Outbound mails. Everything seems to be working fine there. 

     

    But we are in the process of upgrading our DLP to v14 and integration with Email Prevent and Clearswift MTA has been as issue. Clearswift uses opportunistic TLS and the current version i.e. DLP v11.6 doesn't require any certification and can negotiate the TLS request but v14 is not able to do so. When I check the EMail_Operation_Log(0) I see: Service Connection Establish; Forward Connection Establish; Forward Connection failed/closing;Service Connection Closing. This is precisely what is hapening as soon as we are moving to the new server. I can establish a Telnet Connection on the MTA on port 10025 from EMail Prevent but there seems to be a disruption on mail flow. No Outgoing email happens when we try. 

     

    From Clearswift perspective, we see the initial Hello//Handshake. And then it asks for TLS v1.0 request and it seems thats when the connection drops. I don't see any X-CFilter Header tag by Symantec DLP as well. I understand this could be a certificate issue but if v11.6 could negotiate the TLS request without any certificates, why can't v14 do it.

    My Server settings are Requestprocessor.AllowExtention - No STARTTLS string; AllowHost - Any; AllowUnauthenticatedConnections - true; MTAresubmit port - 25; ServerSocketPort - 10025.

     

    Please help.

     



  • 2.  RE: Symantec DLP Email Prevent integration with MTA
    Best Answer

    Posted Aug 22, 2016 09:04 AM

    If you take out the STARTTLS portion of things it should work.  However at this point it won't be doing any TLSconnections.  I would open up a support ticket



  • 3.  RE: Symantec DLP Email Prevent integration with MTA
    Best Answer

    Trusted Advisor
    Posted Aug 23, 2016 02:51 AM

    hello,

    Did you also update your clearswift configuration to add DLP v14 as a TLS endpoint in opportunistic mode (especially if it is a new server) ?

    "I can establish a Telnet Connection on the MTA on port 10025 from EMail Prevent". From prevent server connection will be done on port 25 on MTA so if it is not a typo, you may test it too.

     

     regards.