Restricting MTA access

Prev Next

You can allow only certain devices to connect and transmit emails to the Email Security - Server appliance. Configure a single IP address or multiple IP addresses in the MTA access restriction list by using the Email Security - Server appliance CLI:

You can specify up to ten IP addresses in the list. Both IPv4 and IPv6 addresses are supported. Separate addresses with a space. The Email Security - Server appliance checks each address for the proper syntax but does not validate the syntax. Trellix recommends that you validate the address or addresses before and after a change is made. By default, there is no access restriction to the MTA interface.

You must telnet to your Email Security - Server appliance from the upstream MTA to verify that the configuration is correct.

Prerequisites

  • Administrator or Operator access to the Email Security - Server appliance.

  • An established connection between the Email Security - Server appliance and the Internet.

  • Enable IPv6 on the Email Security - Server appliance. For details about how to enable IPv6 routing, refer to the "Basic Network Configuration" chapter of the System Administration Guide.

  • Enable IPv6 on the SMTP interface if you want to configure one static IPv6 address. For details, refer to the "Basic Network Configuration" chapter Email Security - Server System Administration Guide.

  • Configure the SMTP (pether3) interface with an IP address and mask length. For details, see Configuring the SMTP interface with an IP address using the Web UI or Configuring the SMTP interface with an IP Address using the CLI.