Configuring Inline with Hygiene mode

Prev Next

Email Security - Cloud with AV/AS integration is enabled by modifying the domain mail exchange (MX) record and allowlisting the Email Security - Cloud IP ranges in Gmail. After Email Security - Cloud and Gmail are integrated, all emails are sent to Email Security - Cloud for AV/AS and advanced threat scanning before being delivered to a domain. Messages identified by Email Security - Cloud as malicious are quarantined. Messages not deemed as threats are forwarded to Gmail for processing.

A Sending Routing Rule is required to redirect internal email traffic to Google instead of Email Security - Cloud. If you do not configure a Sending Routing Rule, internal mail will be routed through Email Security - Cloud.

To enable outbound email scanning, you need to configure your existing inbound domain with outbound policies. Refer to Outbound email scanning for the process.

To configure Inline with Hygiene mode:

What you need

  • Administrative access to your Gmail account.

  • Administrative access to your Email Security - Cloud instance.

Step 1: Create the Inbound gateway rule in Gmail

  1. Log in to the Google Admin Console: admin.google.com.

  2. Follow steps 1-4 under "Set up an inbound gateway" in the Google documentation.

  3. For step 5, enter the following configuration settings:

    1. Add IP addresses:

      1. Under Gateway IPs, click Add.

      2. Depending on the geographic region of your Email Security - Cloud account, enter the following IP addresses:

        Email Security - Cloud region

        IP Addresses

        US

        34.223.36.0/24

        3.93.93.0/24

        EMEA

        3.123.5.0/24

        63.34.218.0/24

        APJ

        3.112.99.0/24

        3.112.100.0/24

        USGOV

        15.200.32.0/24

        CA

        3.97.208.0/24

      3. Click Save.

        Note

        If your geographic region has multiple IP ranges, you must repeat steps ai-aiii for each individual IP range. For example, EMEA users must complete these steps two times while USGOV users must only complete these steps once.

    2. Add the Google IP ranges to the Inbound gateway rule.

      1. Follow "Find Google Workspace IP address ranges" in the Google documentation to find the IP address ranges.

      2. Under Gateway IPs, click Add.

      3. Enter the IPs addresses of the Google Workspace mail servers found in step bi.

      4. Click Save.

        Note

        You must repeat steps bii-biv for each individual IP range.

    3. Add the IPv4 and IPv6 addresses.

      1. Under Gateway IPs, click Add.

      2. Enter the following IPs:

        IPv4

        IPv6

        108.177.16.0/24

        2600:1901:101::0/126

        108.177.17.0/24

        2600:1901:101::4/126

        142.250.220.0/24

        2600:1901:101::8/126

        142.250.221.0/24

        2600:1901:101::c/126

        2600:1901:101::10/126

        2600:1901:101::14/126

      3. Click Save.

        Note

        You must repeat steps ci-ciii for each individual IP range.

    4. Verify that the Automatically detect external IP option is unchecked.

    5. Verify that the Reject all mail not from gateway IPs option is unchecked.

    6. Verify that the Require TLS for connections from the email gateways listed above option is unchecked.

  4. Click Save.

Step 2: Create the Google host in Gmail

  1. Log in to the Google Admin Console: admin.google.com.

  2. Follow steps 1-3 under "Add a mail route for your domain" in the Google documentation.

  3. For step 4, enter the following configuration settings:

    1. For Name, enter Google Internal.

    2. Select Multiple hosts.

    3. Under Primary, enter aspmx.l.google.com in the Enter host name or IP entry box.

    4. For Port, enter 25.

    5. Click Add Primary.

    6. Repeat steps 3c-3e for the following:

      • alt1.aspmx.l.google.com

      • alt2.aspmx.l.google.com

      • alt3.aspmx.l.google.com

      • alt4.aspmx.l.google.com

    7. Verify that the Require mail to be transmitted via a secure (TLS) connection option is checked.

    8. Verify that the Require CA signed certificate option is checked.

  4. Click Save.

Step 3: Create the routing rule in Gmail

  1. Log in to the Google Admin Console: admin.google.com.

  2. Follow steps 1-4 under "Add a routing setting" in the Google documentation.

  3. For step 5, enter the following configuration settings:

    1. For the required description, enter Internal Routing.

    2. Under Email Messages to affect, select Internal - Sending.

    3. Under For the above types of messages, do the following, ensure that Modify Messages is selected from the drop-down menu.

    4. Under Route, select Change Route.

      1. Select Suppress bounces from this recipient.

      2. Click the drop-down menu and select Google Internal.

    5. Scroll to the bottom of the page and click Show options.

    6. Under Account types to affect, select Users and Groups.

    7. Under Envelope filter, select Only affect specific envelope senders.

      1. Click the drop-down menu and select Pattern match.

      2. Under Regexp, enter ".*".

  4. Click Save.

Step 4: Modify the domain MX records

Depending on the geographic region of your Email Security - Cloud account, add the following MX records according to priority. Details on modifying MX records are beyond the scope of this document. Contact your domain registrar for more information.

Email Security - Cloud region

MX records

US

primary.us.email.fireeyecloud.com (Priority 10)

alt1.us.email.fireeyecloud.com (Priority 20)

alt2.us.email.fireeyecloud.com (Priority 30)

alt3.us.email.fireeyecloud.com (Priority 40)

EMEA

primary.emea.email.fireeyecloud.com (Priority 10)

alt1.emea.email.fireeyecloud.com (Priority 20)

alt2.emea.email.fireeyecloud.com (Priority 30)

alt3.emea.email.fireeyecloud.com (Priority 40)

APJ

primary.ap.email.fireeyecloud.com (Priority 10)

alt1.ap.email.fireeyecloud.com (Priority 20)

alt2.ap.email.fireeyecloud.com (Priority 30)

alt3.ap.email.fireeyecloud.com (Priority 40)

USGOV

primary.us.etp.fireeyegov.com (Priority 10)

alt1.us.etp.fireeyegov.com (Priority 20)

alt2.us.etp.fireeyegov.com (Priority 30)

alt3.us.etp.fireeyegov.com (Priority 40)

CA

primary.ca.email.fireeyecloud.com (Priority 10)

alt1.ca.email.fireeyecloud.com (Priority 20)

alt2.ca.email.fireeyecloud.com (Priority 30)

alt3.ca.email.fireeyecloud.com (Priority 40)