You can configure Trellix DLP Network Prevent – SaaS for authenticated email submission in scenarios where network policies do not allow email communication on port 25. You can also use this configuration when it is mandatory to use authenticated mail submission.
Make sure that the configured Smart Host supports LOGIN mechanism for authentication.
The default port for authenticated mail submission is 587.
If the Smart Host configuration includes a port number, make sure that the configured port supports LOGIN mechanism for authentication. For example, in 1.2.3.4:50, port 50 must support LOGIN mechanism.
When this feature is enabled, Trellix DLP Network Prevent – SaaS listens on port 587 to accept emails using the supported authentication mechanisms. Trellix DLP Network Prevent – SaaS currently supports only the LOGIN mechanism for SMTP AUTH.
For emails received on port 587, Trellix DLP Network Prevent – SaaS expects the inbound MTA to use LOGIN mechanism to provide the user name and password details. Trellix DLP Network Prevent – SaaS then connects to port 587 or the port specified in the Smart Host configuration of the outbound MTA (Smart Host). It then uses these logon credentials (via LOGIN mechanism) while delivering the email.
The authentication of the user name and password sent by the inbound MTA typically happens in the Smart Host when the appliance delivers the email to the Smart Host. Trellix DLP Network Prevent – SaaS doesn't store the user name and password details.
Note
Trellix DLP Network Prevent – SaaS implicitly mandates Transport Layer Security (TLS) for both inbound and outbound communication when authenticated email submission is enabled. The Transport Layer Security settings in DLP Appliance Management <version> → Trellix DLP Network Prevent Email Settings are not used for authenticated email submission.
In ePO - SaaS, select Menu → Policy → Policy Catalog.
In Product → DLP Appliance Management, select the Trellix DLP Network Prevent Email Settings category, and open the policy you want to edit.
In the SMTP field, select the Enable Authenticated Mail Submission (Uses SMTP AUTH over TLS on port 587) checkbox.
Click Save.