Configuring Inline mode

Prev Next

Cloud MVX Analysis in inline mode provides active (inline) analysis of incoming email to identify advanced threats. Malicious email is blocked.

Important

Failure to properly complete the following steps may result in disruption of message deliveries or loss of messages.

To configure Inline mode, do the following in your MTA:

  1. Set the next hop in your AV/AS gateway to either an MX record or an A record, depending on the region of your account and the type of DNS lookup your AV/AS gateway supports:

    US MX records (preferred):

    • mx.us.email.fireeyecloud.com

    US A records (all 4 entries are required):

    • primary.us.email.fireeyecloud.com (priority 10)

    • alt1.us.email.fireeyecloud.com (priority 20)

    • alt2.us.email.fireeyecloud.com (priority 30)

    • alt3.us.email.fireeyecloud.com (priority 40)

    USGOV MX records (preferred):

    • mx.us.etp.fireeyegov.com

    USGOV A records (all 4 entries are required):

    • primary.us.etp.fireeyegov.com (priority 10)

    • alt1.us.etp.fireeyegov.com (priority 20)

    • alt2.us.etp.fireeyegov.com (priority 30)

    • alt3.us.etp.fireeyegov.com (priority 40)

    EMEA MX records (preferred):

    • mx.emea.email.fireeyecloud.com

    EMEA A records (all 4 entries required):

    • primary.emea.email.fireeyecloud.com (priority 10)

    • alt1.emea.email.fireeyecloud.com (priority 20)

    • alt2.emea.email.fireeyecloud.com (priority 30)

    • alt3.emea.email.fireeyecloud.com (priority 40)

    APJ MX records (preferred):

    • mx.ap.email.fireeyecloud.com

    APJ A records (all 4 entries required):

    • primary.ap.email.fireeyecloud.com

    • alt1.ap.email.fireeyecloud.com

    • alt2.ap.email.fireeyecloud.com

    • alt3.ap.email.fireeyecloud.com

    CA MX records (preferred):

    • mx.ca.email.fireeyecloud.com

    CA A Records (all 4 entries required):

    • primary.ca.email.fireeyecloud.com

    • alt1.ca.email.fireeyecloud.com

    • alt2.ca.email.fireeyecloud.com

    • alt3.ca.email.fireeyecloud.com

  2. Configure your firewall to allow incoming TCP traffic on port 25 to your MTA from the following IP addresses, depending on the Email Security — Cloud region of your account:

    • USA:

      • 34.223.36.0/24

      • 3.93.93.0/24

    • USGOV:

      • 15.200.32.0/24

    • EMEA:

      • 3.123.5.0/24

      • 63.34.218.0/24

    • APJ:

      • 3.112.99.0/24

      • 3.112.100.0/24

    • CA:

      • 3.97.207.0/24

  3. Disable any SPF, DKIM, DMARC, RBL, DHAP, and PTR record checks, GeoIP checks, antispam engines, antivirus engine, and mail throttling rules for messages received from the following IP addresses, depending on the Email Security — Cloud region of your account:

    • USA:

      • 34.223.36.0/24

      • 3.93.93.0/24

    • USGOV:

      • 15.200.32.0/24

    • EMEA:

      • 3.123.5.0/24

      • 63.34.218.0/24

    • APJ:

      • 3.112.99.0/24

      • 3.112.100.0/24

    • CA:

      • 3.97.207.0/24

  4. Allowlist any traffic originating from the following IP addresses, depending on the Email Security — Cloud region of your account:

    • USA:

      • 34.223.36.0/24

      • 3.93.93.0/24

    • USGOV:

      • 15.200.32.0/24

    • EMEA:

      • 3.123.5.0/24

      • 63.34.218.0/24

    • APJ:

      • 3.112.99.0/24

      • 3.112.100.0/24

    • CA:

      • 3.97.207.0/24

  5. In the Email Security - Cloud Web portal, create an email routing policy for a domain using the instructions in Email routing configuration policies.

  6. In the Email Security - Cloud Web portal, follow the prompts to provision the domain.