Configuring Inline mode

Prev Next

Trellix Email Security - Cloud Inline mode is enabled by adding rules to Gmail and allowlisting the Email Security - Cloud IP ranges in Gmail's service. After successful integration, email sent to your organization's domains goes through Gmail for antispam and antivirus scanning before going through Email Security - Cloud for advanced threat detection. Messages identified as advanced threats by Email Security - Cloud are quarantined and messages identified as spam or viruses are quarantined by Gmail. Email that is not identified as a threat by either service is delivered to recipient mailboxes by Gmail.

Important

When Gmail scans email from Email Security - Cloud with SPF/DKIM/DMARC, a notification is sent indicating failure. However, Gmail still accepts email from Email Security - Cloud as long as IP addresses are correctly listed in the Inbound Gateway field.

Headers are used to determine whether email should be routed to Email Security - Cloud. It is possible to bypass Email Security - Cloud scanning if emails are sent with your organization's X-Header included. Trellix recommends that X-Headers do not include indicators of what the header is being used for. By default, X-Headers are removed from email replies. However, if an email is downloaded, then attached to a new email, the X-Header may be exposed publicly.

To configure Inline mode:

What you need

  • Administrative access to your Gmail account.

  • Administrative access to your Email Security - Cloud instance.

Step 1: Create the Inbound gateway rule in Gmail

  1. Log in to the Google Admin Console: admin.google.com.

  2. Follow steps 1-4 of "Set up an inbound gateway" in the Google documentation.

  3. For step 5, enter the following configuration settings:

    1. Under Gateway IPs, click Add.

    2. Depending on the geographic region of your Email Security — Cloud account, enter the following IP addresses:

      Email Security - Cloud region

      IP addresses

      US

      34.223.36.0/24

      3.93.93.0/24

      EMEA

      3.123.5.0/24

      63.34.218.0/24

      APJ

      3.112.99.0/24

      3.112.100.0/24

      USGOV

      15.200.32.0/24

      CA

      3.97.207.0/24

    3. Click Save.

      Note

      If your geographic region has multiple IP ranges, you must repeat steps 3a through 3c for each individual IP range. For example, EMEA users must complete these steps two times while CA users must only complete these steps once.

    4. Verify that the Automatically detect external IP option is unchecked.

    5. Verify that the Reject all mail not from gateway IPs option is unchecked.

      Note

      If Reject all mail not from gateway IPs is selected, internal mail delivery will be disrupted.

    6. Verify that the Require TLS for connections from the email gateways listed above option is unchecked.

  4. Click Save.

Step 2: Create the Email Security - Cloud host in Gmail

Note

This automatically configures the host for failover using the pre-configured Email Security - Cloud MX records.

  1. Log in to the Google Admin Console: admin.google.com.

  2. Follow steps 1-3 under "Add a mail route for your domain" in the Google documentation.

  3. For step 4, enter the following configuration settings:

    1. For Name, enter Email Security - Cloud.

    2. For Specify email server, select Single host.

    3. Depending on the geographic region of your Email Security - Cloud, enter the following MX record in the Enter host name or IP entry box:

      Email Security - Cloud region

      Server name

      US

      mx.us.email.fireeyecloud.com

      EMEA

      mx.emea.email.fireeyecloud.com

      APJ

      mx.ap.email.fireeyecloud.com

      USGOV

      mx.us.etp.fireeyegov.com

      CA

      mx.ca.etp.fireeyecloud.com

    4. For the port, enter 25.

    5. Verify that the Perform MX lookup on host option is selected.

    6. Verify that the Require mail to be transmitted via a secure (TLS) connection option is selected.

    7. Verify that the Require CA signed certificate option is selected.

  4. Click Save.

Step 3: Create the content compliance rule in Gmail

Important

Refer to "Set up a content compliance rule" in the Google documentation for the following steps.

  1. Log in to the Google Admin Console: admin.google.com.

  2. Under "Step 1: Go to Gmail Compliance settings in the Google Admin console", follow steps 1-4.

  3. In the description entry box, enter Route inbound email to Email Security - Cloud.

  4. Under Email messages to affect, select Inbound.

  5. Under Add expressions that describe the content you want to search for in each message, select If ANY of the following match the message from the drop-down.

  6. Click ADD, then enter the following configuration settings:

    1. Change the selector to Advanced content match.

    2. For Location, select Full headers.

    3. For Match Type, select Not matches regex.

    4. For Regexp, enter ^X-Secret-Header: <secret_value>.

      Note

      You must choose an X-Header name and value to enter in this step. The header you choose should be something that is only meaningful to your organization. The header you choose will be used to route email between Gmail and Email Security - Cloud and can be abused if exposed. Trellix strongly recommends not using the example provided in step 6d.

      Trellix Email Security - Cloud uses the X-Secret-Header to prevent redundant email scanning. The system removes this header during the scanning process. If the header is missing when the email leaves the system, the email routes back to the scanner and creates a mail loop.The system also reserves the X-ETP-* prefix for internal use. Trellix Email Security - Cloud removes any pre-existing X-ETP-* headers when it accepts a message.

    5. Click Save to save the match condition.

  7. Under If the above expressions match, do the following, select Modify Message from the drop-down.

  8. Under Headers, configure the the following settings:

    1. Select Add X-Gm-Original-To header.

    2. Select Add X-Gm-Spam and X-Gm-Phishy headers.

    3. Select Add custom headers, then add the header you added in step 6d.

    4. Click Save.

  9. Under Route, configure the following settings:

    1. Select Change route.

    2. Verify that the Also reroute spam option is unchecked.

    3. Select Email Security - Cloud from the drop-down menu.

  10. Scroll to the bottom of the window, then click Show options.

  11. Under Account types to affect:

    1. Select Users.

    2. Select Groups.

  12. Click Save.