Enable TLS on incoming or outgoing messages

Prev Next

You can specify whether Trellix DLP Network Prevent – SaaS uses TLS to protect incoming and outgoing messages, or only uses TLS when it is available (known as Opportunistic). A minimum protocol version of TLS 1.1 is used.

Trellix DLP Network Prevent – SaaS can perform cryptographic operations in a way that is compliant with FIPS 140-2. This means that incoming and outgoing TLS connections use high-strength cryptographic algorithms.

Important

Using FIPS 140-2 can impact performance when analyzing SMTP content.

The option to enable FIPS 140-2 is located in the General category of the DLP Appliance Management product in the Policy Catalog. Due to the nature of FIPS 140-2, enabling this feature decreases your appliance's throughput.

TLS works by communicating a set of parameters — known as a handshake — at the start of a connection between participating servers. When these parameters are defined, communications between the servers become secure so that servers that did not participate in the handshake can't decode them.

The handshake process

  • The appliance requests a secure connection to the receiving email server and presents it with a list of cipher suites.

  • The receiving server selects the strongest supported cipher from the list, and gives the details to the appliance.

  • The servers use the Public Key Infrastructure (PKI) to establish authenticity by exchanging digital certificates.

  • Using the server's public key, the appliance generates a random number as a session key and sends it to the receiving email server. The receiving server decrypts the key using the private key.

  • Both the appliance and the receiving email server use the encrypted key to set up communications and complete the handshake process.

Once the handshake is complete, the secure connection is used to transfer the email messages. The connection remains secure until the connection is closed.

Note

If you select the Always option for outbound communications, but the Smart Host is not configured to use TLS, Trellix DLP Network Prevent – SaaS sends a 550 x.x.x.x: Denied by policy. TLS conversation required error.

  1. In ePO - SaaS, open the Policy Catalog.

  2. Select the DLP Appliance Management product, choose the Trellix DLP Network Prevent Email Settings category, and open the policy that you want to edit.

  3. In Transport Layer Security, select either Always or Opportunistic for inbound communications.

    Opportunistic is the default setting.

  4. Select either Always or Opportunistic for outbound communications.

    Opportunistic is the default setting.

  5. Click Save.