Instructions for Configuring Microsoft Exchange 2003 For Outbound smarshdlp/encrypt Versions Addressed: Microsoft Exchange 2003 Document Updated: March 25, 2015 Co nfidential Copyright 2015 Smarsh, Inc. All Purpose: This document will assist the end user in configuring smarshencrypt for Microsoft Exchange 2003.
Tables of Contents Add new Archive Send Connector for Encryption with Archiving... 4 Add new Encryption Send Connector with existing Journaling rule... 6 Add a new Send Connector for using Encryption only... 9 Verification of messages correctly traveling through Smarsh s smart host... 11 Page 2 of 11
This document is intended to serve as a guide for configuring the Microsoft Exchange Send Connector feature to enable email encryption with Smarsh. If you need assistance with this process please reference Support for Microsoft Exchange Server or contact Microsoft Support. The instructions that follow are based upon Microsoft Exchange 2003. You will need the following information (which has been provided to you in an email): Your fully qualified domain name (FQDN): obsmtp01.smarsh.com Your journaling address space: yourdomain.journaltosmarsh.com If you already have any existing Enabled Send Connectors, they may conflict with the ones that you are about to create. Please ensure with your best judgment how to proceed with managing your current connectors, with these new ones. Page 3 of 11
**NOTICE** You will need to choose the correct path to ensure proper routing of outbound emails and journaling. If you have encryption only, will just be adding 1 Send Connector. This will create a total of 2 Send Connectors, to ensure the journaled messages travel directly out through the internet. This prevents journaled messages traveling through the outbound relay, along with regular messages. If you are setting up only encryption, and you are not journaling to Smarsh, go to page 9, and follow the instructions from that point. Add new Archive Send Connector for Encryption with Archiving This is not absolutely required in order to archive all messages for compliance; however by routing outbound messages through your SMTP Connector with TLS Encryption turned on your exchange server will utilize 128bit encryption when sending journaled e-mails to the Smarsh archive server. 1) In Exchange System Manager right click on Connectors and choose new SMTP Connector. 2) Name your SMTP Connector and Add the appropriate local bridgehead: Page 4 of 11
3) In the Address Space tab check the box Allow Messages to be relayed a. Click ADD button choose type SMTP Address Space b. 4) Enter E-mail domain: (Address Space provided in the accompanying email) click OK Page 5 of 11
5) In the Advanced tab click on the Outbound Security button a. Check the TLS encryption box i. Click OK and OK again Add new Encryption Send Connector with existing Journaling rule 6) Create a new SMTP Connector, and name it something like smarshencrypt Page 6 of 11
7) Check the box Forward all mail through this connector to the following smart hosts, and enter obsmtp01.smarsh.com. a. Assign your local server to the Local Bridgehead section. 8) Open the Address Space tab and add a new address space entry. Choose type SMTP, use the asterisk (*) symbol as the domain, and assign the cost of 2. Page 7 of 11
9) In the Advanced tab click on the Outbound Security button a. Check the TLS encryption box All of your outbound messages will now travel through Smarsh s smart host. All of your journaling messages will now travel directly to the internet. Please review the email we have sent you regarding your encryption rules, and how to trigger the service. Page 8 of 11
Add a new Send Connector for using Encryption only 1) Create a new SMTP Connector, and name it smarshencrypt 2) Check the box Forward all mail through this connector to the following smart hosts, and enter obsmtp01.smarsh.com. a. Assign your local server to the Local Bridgehead section. Page 9 of 11
3) Open the Address Space tab and add a new address space entry. Choose type SMTP, use the asterisk (*) symbol as the domain, and assign the cost of 1. 4) In the Advanced tab click on the Outbound Security button a. Check the TLS encryption box All of your outbound messages will now travel through Smarsh s smart host. Please review the email we have sent you regarding your encryption rules, and how to trigger the service. Page 10 of 11
Verification of messages correctly traveling through Smarsh s smart host To test your configuration send a few test messages from your domain. Then email back on your implementation case asking Smarsh to confirm. If you currently have an SPF record setup for your domain. You will need to update this SPF record to the following: v=spf1 include:spf.smarsh.com all * The SPF record can be updated where your domain s DNS is currently being hosted. Please see the following article if you have questions about creating send connectors: http://support.microsoft.com/en-us/kb/265293 Page 11 of 11