eprism installation guide · 2016-10-03 · 3 preface preface this installation guide provides...

39
ePrism Installation Guide M1000, M2000, M3000

Upload: others

Post on 19-Apr-2020

12 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

ePrism Installation Guide

M 1 0 0 0 , M 2 0 0 0 , M 3 0 0 0

Page 2: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism
Page 3: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Preface 3

CHAPTER 1 Pre-Installation Tasks 5ePrism Deployment 6Network Modifications 8Firewall Configuration 9DNS Configuration for Mail Routing 10Hardware Installation 11

CHAPTER 2 Installing ePrism 13Installing ePrism from the System Console 14Connecting to ePrism via a Web Browser 19

CHAPTER 3 Post-Installation Tasks 23Licensing ePrism 24Software Updates 26Security Connection 27

CHAPTER 4 Configuring Mail Delivery 29Network Settings 30Static Routes 32Mail Routing 33Modify Internal Mail Servers 34Starting Mail Services 35

1

Page 4: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

2

Page 5: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Preface

PrefaceThis Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism Email Security Appliance.

When the initial setup is complete, see the ePrism User Guide for more detailed information on ePrism configuration and administration.

The Installation Guide contains the following topics:

• Chapter 1 — “Pre-Installation Tasks” on page 5• Chapter 2 — “Installing ePrism” on page 13• Chapter 3 — “Post-Installation Tasks” on page 23• Chapter 4 — “Configuring Mail Delivery” on page 29

Related Documentation

If release notes are included with your product package, please read them for the latest information on installing and managing your ePrism.

The following documents are included as part of the ePrism documentation set:

• Release Notes — Provides up to date information on the product, including any known issues. If instructions in the release notes differ from the Installation Guide or User Guide, use the instructions in the Release Notes.

• Installation Guide — Provides instructions on how to install and provide the initial configuration for the ePrism Email Security Appliance.

• User Guide — Provides detailed information on how to configure and administer the ePrism Email Security Appliance.

Contacting Technical Support

St. Bernard Software telephone support is available Monday-Friday 07:00am to 4:00pm (Pacific Standard Time) 08:30 to 17:30 (UTC) North America, South America, Pacific Rim (PST)

15015 Avenue of Science San Diego, CA 92128 Main: 858.676.2277 FAX: 858.676.2299 Technical Support: 858.676.5050 Technical Support Email: [email protected]

3

Page 6: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

4

Europe, Asia, Africa (UTC) Unit 4, Riverside Way Watchmoor Park, Camberley Surrey, UK GU15 3YQ

Main: 44.1276.401.640 FAX: 44.1276.684.479 Technical Support: 44.1276.401.642 Technical Support Email: [email protected]

Copyright Information

© 2003-2005 St. Bernard Software, Inc. All rights reserved.

St. Bernard Software is trademark of St. Bernard Software Inc. All other trademarks or registered trademarks are hereby acknowledged.

Information in this document is subject to change without notice.

Page 7: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

CHAPTER 1 Pre-Installation Tasks

This chapter contains information on the pre-installation tasks that need to be completed before installing the ePrism Email Security Appliance, and includes the following topics:

• “ePrism Deployment” on page 6• “Network Modifications” on page 8• “Firewall Configuration” on page 9• “DNS Configuration for Mail Routing” on page 10• “Hardware Installation” on page 11

5

Page 8: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Pre-Installation Tasks

6

ePrism Deployment

ePrism is designed to be situated between your mail servers and the Internet so that there are no direct SMTP (Simple Mail Transport Protocol) connections between external and internal servers.

ePrism is typically installed in one of three locations:

• In parallel with the firewall• On your DMZ (Demilitarized Zone)• Behind the existing firewall on the Internal network

SMTP port 25 traffic is redirected from either the external interface of the firewall, or from the external router to ePrism. When the mail is accepted and processed, ePrism initiates an SMTP connection to the internal mail server to deliver the mail.

ePrism in Parallel with the Firewall

The preferred deployment strategy for ePrism is to be situated in parallel with an existing network Firewall. ePrism’s inherent firewall security architecture eliminates the risk associated with deploying an appliance on the perimeter of your network. This parallel deployment eliminates any mail traffic on the firewall and decreases its overall load.

In this configuration, one network card is configured to connect to the Internet, and a second network card is configured to connect to the internal network.

Page 9: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

ePrism Deployment

ePrism on the DMZ

Deploying ePrism on the DMZ (Demilitarized Zone) is an equally secure method of deployment configuration. This type of deployment on the secure DMZ network off of the network firewall prevents any direct connection from the Internet to the internal mail servers, but does not ease the existing network load on the firewall.

ePrism must be assigned an IP address that is accessible from the Internet, usually via Network Address Translation (NAT) or other similar networking technique. A second network card should be configured to connect directly to the internal network and eliminate routing mail through the firewall a second time.

ePrism on the Internal Network

You can also deploy ePrism on your internal network. Although this configuration allows a direct connection from the Internet into the internal network, it is a perfectly legitimate configuration when dictated by existing network resources.

7

Page 10: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Pre-Installation Tasks

8

Network Modifications

When you have decided on an ePrism deployment strategy, the following information about your environment needs to be gathered to ensure a smooth implementation.

In this section, you will:

• Collect necessary network settings• Determine which ports need to be opened on the Firewall• Determine appropriate DNS settings for mail routing• Identify changes required to the internal mail servers for outbound mail.

Network Parameter Settings

When initializing ePrism for the first time, you will need to have the following information on hand:

• Hostname — The hostname assigned to the ePrism, such as eprism in the fully qualified domain name eprism.example.com.

• Domain Name — The domain name associated with the assigned hostname. This is typically the domain that email is being processed for, such as example.com.

• IP Address — Select an IP address for ePrism. Depending on your deployment, you may need addresses for multiple network interface cards. For example, in a parallel deployment with the network firewall, you will need an external and internal IP address.

• Subnet Mask — This is the subnet mask for the IP address you have chosen.• Gateway Address — The default gateway for ePrism. In most cases, this is your router.

Additional Networking and Mail Delivery Information

The following information will be required later in the installation procedure:

• The mail domain name(s) the ePrism will be processing mail for.• The domain name or IP address of your internal mail servers that will be receiving and sending

mail via ePrism.• The IP address, Subnet Mask, and Gateway Address for any additional network cards required

by your choice of deployment.• The address of NTP (Network Time Protocol) servers for time synchronization.

Page 11: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Firewall Configuration

Firewall ConfigurationFor ePrism to process mail effectively, various networking ports need to be configured on your network firewall to allow connectivity for mail processing purposes. If you are not using some of the features listed in the following table, the corresponding ports can remain closed.

The following table describes the list of ports required for each service:

* Although available, these options are not recommended. Secure versions of these ports are available.

TABLE 1. Network Firewall Port Settings

Port DescriptionFrom Internet

To Internet

From Internal Network

To Internal Network Protocol

21 FTP for System Backups ✔ TCP

25 SMTP ✔ ✔ ✔ ✔ TCP

53 DNS ✔ ✔ UDP

80 Anti-Virus Updates ✔ TCP

80 Web Mail Access - OWA, iNotes (* see 443 Secure Web Mail)

✔ ✔ TCP

110 POP3 (* see 995 Secure POP3)

✔ ✔ TCP

123 Network Time Protocol ✔ ✔ UDP

143 IMAP Proxy ✔ ✔ TCP

443 ePrism Software Updates ✔ TCP

443 Secure Web Mail Access ✔ ✔ TCP

443 Secure Web Based Administration

✔ ✔ TCP

514 Syslog ✔ UDP

993 Secure IMAP ✔ ✔ TCP

995 Secure POP3 ✔ ✔ TCP

1812 RADIUS Server ✔ UDP

5500 RSA Secure ID ACE Server

✔ UDP

6277 Distributed Checksum Clearinghouse (DCC) checks

✔ UDP

9

Page 12: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Pre-Installation Tasks

10

DNS Configuration for Mail Routing

DNS services are used to route mail from the Internet to ePrism. DNS configurations can be quite complex, and are usually dependant on your specific site’s networking environment. The following instructions represent the minimum changes required to get mail routed to the ePrism. For further information, please contact your network administrator.

As a minimum, an MX (mail exchanger) record should be added to forward incoming mail to ePrism:

example.com. IN MX 0 eprism.example.com

An "A" record should be added to resolve the domain name to an IP address:

eprism.example.com. IN A 192.168.0.2

A PTR record should be added to allow reverse look-ups to succeed and prevent mail sent from the ePrism being marked as suspected spam:

2.0.168.192.in-addr.arpa. IN PTR eprism.example.com

Consider keeping an MX record with a higher preference pointed at your current mail server during the integration phase. If the ePrism is taken out of service, mail will automatically route directly to the mail server. This entry should be deleted before you move to a production environment as spammers could find this alternate route and bypass ePrism.

example.com. IN MX 10 mailserver.example.com

Outbound Mail Routing

While DNS entries are required to route inbound mail through the ePrism, changes are required to the existing internal mail server(s) to route outbound mail through the ePrism.

All internal systems should be configured to use ePrism for delivery, allowing internal mail content to be processed for attachments and viruses to prevent the spread of viruses introduced locally. This feature is also used to improve the spam detection capabilities of the Statistical Token Analysis (STA) engine.

Page 13: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Hardware Installation

Hardware InstallationFollow the instructions in the hardware setup guide included in the shipping box to rack mount the ePrism Email Security Appliance.

Physical Location

As ePrism will handle all of your inbound and outbound email, it is important that some consideration is given to its physical security to protect against unauthorized tampering which could compromise system security. St. Bernard Technologies recommends the following:

• ePrism should be installed in a secure location, preferably in a locked equipment rack or secure server room.

• Ensure that the network connections are secure, and that network hubs and switches are located within the same equipment rack or secure server room. Any network patch cables should be of the appropriate length, preferably as short as possible.

• If a monitor and keyboard are attached to ePrism for console use, ensure that they are connected directly to ePrism to prevent the possibility of keystroke logging devices from being introduced in the keyboard connection.

• Use the Web Admin interface in a secure location and restrict its use to trusted workstations. Never use the Web Admin interface in locations where the administrative session could be monitored physically or electronically in any manner.

Connect Monitor, Keyboard, and Mouse

For the initial configuration, a monitor and keyboard are required to operate the ePrism console. A mouse can also be installed if needed. After the initial configuration, the system can be managed remotely.

Connect the Network Interfaces

Before installation, you should ensure that at least one of the network interfaces is physically connected to the network. You will be able to more easily confirm that you have correctly identified the system on the network and ensure connectivity.

11

Page 14: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Pre-Installation Tasks

12

Page 15: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

CHAPTER 2 Installing ePrism

When you have completed your pre-installation tasks and have all the information you need for the initial configuration of the ePrism Email Security Appliance, you are now ready for the installation.

The installation includes the following steps:

• “Installing ePrism from the System Console” on page 14• “Connecting to ePrism via a Web Browser” on page 19

13

Page 16: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Installing ePrism

14

Installing ePrism from the System Console

Start the initial console installation for ePrism as follows:

1. Ensure the power cable and network cables are connected to ePrism.2. Turn on the system.3. You will see the following options at startup:

F1 Restore — Restore is used to reinstall the system to factory default settings.F2 ePrism — The ePrism option will load the existing ePrism installation. This option will be chosen by default after a few seconds.F3 Diag — This option is used to access the diagnostics partition of your server if one has been installed by the manufacturer.

4. Press F2 ePrism or wait for the option to be automatically selected.5. Choose a Graphical or Text Mode installation. Use Text mode if you are experiencing display

problems with the graphical mode.6. Choose the keyboard type that matches your location.7. Select the disk installation type:

• Auto — Default values for disk space allocation for log file storage, mail storage, backup area, and database area are used.

• Custom — Allows you to modify values for disk space allocation. To edit the default space allocation values, select Custom and press Enter. The system will warn you that it will erase all data on the hard disks. Select OK to continue.Select the target installation hard disk and select OK to continue.Select New Software Installation.

Page 17: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Installing ePrism from the System Console

Enter the values for your disk geometry, and select OK to continue.

8. Select from the following installation types:CD-ROM — Install from a CD-ROM ISO image.Hard Disk — Install from a software image already loaded on the ePrism hard disk.Network — Install a software image file from a network location.

9. Select Hard Disk to install from the image installed on the system by the manufacturer.10. When the software image is loaded, the system will ask you to confirm the amount of system

memory.11. Click OK to restart the system.12. Select the disk installation type:

15

Page 18: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Installing ePrism

16

• Auto — Default values for disk space allocation for log file storage, mail storage, backup area, and database area are used.

• Custom — Allows you to modify values for disk space allocation. To edit the default space allocation values, select Custom. The hard disk will be detected and identified. Select Continue.

Select Edit to edit the disk layout.

Use the arrow keys to move between fields. Press Enter to use the displayed action such as "+ 1", "+ 10", and so on. The values are in megabytes.

You will need to decrease the amount allocated to one file system before increasing another. When finished, select Done, and then OK to exit the disk layout screen.Select Yes to proceed with erasing the hard disks.

13. You will be prompted with the Network Settings screen.

Page 19: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Installing ePrism from the System Console

If you need to reset the settings to the defaults, press Esc.

• Network Interface — Select the network interface to configure.• Hostname — Enter the hostname for the system, such as eprism in the fully qualified domain

name eprism.example.com.• Domain Name — Enter your domain, such as example.com.• IP Address — Enter the IP address for this interface, such as 192.168.1.128.• Subnet mask — Enter the subnet mask, such as 255.255.255.0.• Gateway — Enter the gateway (typically the router) for your network.• Name Server — Enter the IP address of your DNS server.

14. Select OK to continue.15. Set the region and time zone.

17

Page 20: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Installing ePrism

18

The initial configuration is now complete, and the main console screen will be displayed.

You may see a message warning that the "Mail System is stopped!". This message is normal because mail services have not been started yet.

You must now connect to ePrism using a web browser to continue with the remainder of the installation.

Page 21: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Connecting to ePrism via a Web Browser

Connecting to ePrism via a Web BrowserFor the remainder of the configuration process, you must connect to ePrism via the web browser administration interface.

1. Launch a web browser on your computer and enter the IP address or hostname for ePrism as the URL in the location bar. Note: Your system must be listed in your DNS server to be able to connect via the hostname.

2. The login screen will then appear. Enter the admin ID and default password admin.

3. When ePrism is installed for the first time, you must complete the initialization phase by accepting the license agreement.

19

Page 22: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Installing ePrism

20

4. Enter the organization name and server administrator email address for this system.

5. You must change the default admin password after you log on. Choose a secure password of at least 8 characters in length, and include a mixture of upper and lowercase alphabetic characters, numbers, and special characters such as the "@" symbol.

Page 23: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Connecting to ePrism via a Web Browser

6. Select your hardware type and usage for the system’s performance settings. Depending on your hardware and the services you want to enable (such as WebMail), ePrism can automatically optimize the performance parameters for this system.

The initial installation is now complete, and the main ePrism Activity screen is then displayed.

Note: The mail system will initially be in a stopped state. You must configure your basic mail delivery settings, as detailed in the next chapter, before starting the mail system.

21

Page 24: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Installing ePrism

22

Page 25: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

CHAPTER 3 Post-Installation Tasks

This chapter contains information on the post-installation tasks that need to be completed after installing the ePrism Email Security Appliance, and includes the following topics:

• “Licensing ePrism” on page 24• “Software Updates” on page 26• “Security Connection” on page 27

23

Page 26: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Post-Installation Tasks

24

Licensing ePrism

The ePrism Email Security Appliance initially starts in evaluation mode which can be used for 30 days. After that time, ePrism stops accepting new mail. Incoming mail will receive an SMTP failure message explaining that no mail is being accepted because the evaluation period has elapsed. Existing mail in the queue will still be delivered, and mail in mailboxes will still be accessible to POP3/IMAP and ePrism Mail Client users.

Use the information in your License Pack to license and activate ePrism. Activating ePrism also activates your support contract which is valid for 12 months from purchase.

Note: Your Support Contract entitles you to all software upgrades and patches, as well as return-to-factory warranty on the hardware. Failure to activate your system may delay the delivery of support services.

ePrism can be licensed both automatically via the Internet and manually. For automatic licensing, ePrism requires an Internet connection.

Automatic License Activation

License ePrism automatically as follows:

1. Ensure that the system can access the Internet so it can connect to the St. Bernard License server.

2. Select Management -> License Management on the menu.

Page 27: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Licensing ePrism

3. Click theObtain Activation Key button. A new web browser window will open up and display the St. Bernard licensing activation screen.

4. Enter the System ID shown on the License Management screen.5. Enter the License serial number from your License Pack. (This is not the hardware serial

number of the system.)6. Enter the Hardware serial number located on the ePrism system.7. Click Submit to receive your Activation Key.

Manual License Activation

To manually activate licenses:

1. From a workstation connected to the Internet, go to St. Bernard’s web site at activate.stbernard.com to obtain an Activation Key.

2. Select the product you want to license, and then enter the appropriate license information.3. You will receive an Activation Key that will be used in the following steps.4. On ePrism, select Management -> License Management on the menu.5. Click the Manual Activation button.6. Enter the Serial number and Activation Key, and then click Next.

25

Page 28: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Post-Installation Tasks

26

Software Updates

To ensure your ePrism software is up to date with the latest patches and upgrades, you should ensure that you install any updates released for your version of ePrism.

Updates are supplied in special files provided by St. Bernard. These updates can be delivered or retrieved using a variety of methods, including email, FTP, or from St. Bernard’s support servers. The Security Connection, if enabled, will download any patches automatically. Security Connection is discussed in more detail in the next section.

Select Management -> Software Updates on the menu to load and apply software updates.

The Software Updates screen shows updates that are Available Updates (loaded onto ePrism, but not applied) and Installed Updates (applied and active). You can install an available update, or uninstall a previously installed update.

When these software update files are downloaded to your local system, they can be installed by clicking Browse, navigating to the downloaded file, and then clicking Upload.

After applying any updates, you must restart the system.

Page 29: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Security Connection

Security ConnectionThe Security Connection is a service running on ePrism that polls St. Bernard’s support servers for new updates, security alerts, and other important information. When new information and updates are received, an email can be sent to the administrator.

It is recommended that you enable this service after installation to ensure you automatically receive notifications for the latest software updates.

Note: For security purposes, all Security Connection files are encrypted, and contain an MD5-based digital signature which is verified after decrypting the file.

• Enabled — Select to enable Security Connection.• Frequency — Specify how often to run the Security Connection service. Choices are daily,

weekly, and monthly.• Auto Download — Enable this option to allow software updates to be downloaded

automatically.• Display Alerts — Enable this option to display any alert messages on the system console.• Send Email — Enable this option to send an email to the address specified below.• Notification Mail Address — Specify an email address to receive messages from Security

Connection.• Support Contract — You must enter a valid Support Contract number. This information is

supplied with your license key at the time of purchase.

Click Update to save your Security Connection configuration.

Click the Connect Now button to run Security Connection immediately.

27

Page 30: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Post-Installation Tasks

28

Page 31: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

CHAPTER 4 Configuring Mail Delivery

You must configure your basic networking and mail delivery settings before ePrism can begin processing mail. This process includes defining the domains that ePrism will accept mail for and configuring your internal mail servers to route outbound mail via ePrism.

This chapter contains the following topics:

• “Network Settings” on page 30• “Static Routes” on page 32• “Mail Routing” on page 33• “Modify Internal Mail Servers” on page 34• “Starting Mail Services” on page 35

29

Page 32: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Configuring Mail Delivery

30

Network Settings

The basic networking information to get ePrism up and running on the network is configured during installation time. To perform more advanced network configuration and to configure other network interfaces, you must use the Basic Config -> Network settings screen.

Note: If you make any modifications to your network settings, you must reboot ePrism. The system will prompt you to restart after clicking the Apply button.

Configuring Network Settings

Select Basic Config -> Network on the menu to configure ePrism’s network settings.

• Hostname — Enter the hostname (not the full domain name) of the ePrism Email Security Appliance, such as eprism in the domain name eprism.example.com.

• Domain — Enter the domain name, such as example.com.• Gateway — Enter the IP address of the default route for ePrism. This is typically the external

router connected to the Internet.• Syslog Host — ePrism can log to a specific syslog host. A syslog host collects and stores log

files from many sources. Enter the IP address of the syslog server that will receive logs from ePrism.

• Name Server — At least one DNS name server must be configured for hostname resolution, and it is recommended that secondary name servers be specified in the event the primary DNS server is unavailable.

Page 33: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Network Settings

• NTP Server — NTP (Network Time Protocol) is critical for accurate timekeeping for the ePrism Email Security Appliance. Entering a valid NTP server will ensure that the server time is synchronized. It is recommended that secondary NTP servers be specified in the event the primary NTP server is unavailable.

Network Interfaces

Enter the required settings for each network interface. You can enter information for up to four interfaces.

• IP Address — Enter an IP address, such as 192.168.1.128, for each interface you require.• Netmask — Enter the netmask for this interface, such as 255.255.255.0.• Media — Select the type of network card. Use Auto select for automatic configuration.• Large MTU — Sets the MTU (Maximum Transfer Unit) to 1500 bytes. This may improve

performance connecting to servers on the local network. The default is 576 bytes.• Respond to Ping — Allows ICMP ping requests to this interface. This will allow you to

perform network connectivity tests to this interface, but will cause this interface to be more susceptible to denial of service ping attacks.

• Trusted Subnet — If selected, all hosts on this subnet are considered trusted for relaying and anti-spam processing.

• Admin Login — Allows access to this interface for administrative purposes.• WebMail — Allows access to WebMail via this interface.• SNMP Agent — Allows access to the SNMP agent via this interface.

31

Page 34: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Configuring Mail Delivery

32

Static Routes

Static routes are required if the mail servers to which mail must be relayed are located on another network, such as behind an internal firewall or accessed via a VPN.

Select Basic Config -> Static Routes to configure your static routes.

To add a new static route, enter the network address, netmask and gateway for the route, and then click New Route.

Page 35: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Mail Routing

Mail RoutingePrism, by default, accepts mail addressed directly to it and delivers it to local ePrism mailboxes. Use the Mail Routing screen to configure additional domains for ePrism to accept and route mail for and what destination mail servers to route the message to.

Select Mail Delivery -> Mail Routing from the menu to set up mail routes.

• Sub — Select this check box to accept and relay mail for subdomains of the specified domain.• Domain — Enter the domain for which mail is to be accepted, such as example.com.• Route-to — Enter the address for the server to which mail will be delivered. This will be the

address of an internal mail server.• MX — (Optional) Select the MX check box if you need to look up the mail routes in DNS

before delivery. If this is not enabled, MX records will be ignored. Generally, you do not need to select this item unless you are using multiple mail server DNS entries for load balancing/failover purposes. By checking the MX record, DNS will be able to send the request to the next mail server in the list.

• KeepOpen — (Optional) Select the KeepOpen check box to ensure that each mail message to the domain will not be removed from the active queue until delivery is attempted, even if the preceding mail failed or was deferred. This setting ensures that local mail servers receive high priority. Note: The KeepOpen option should only be used for domains that are usually very reliable. If the domain is unavailable, it may cause system performance problems due to excessive error conditions and deferred mail.

33

Page 36: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Configuring Mail Delivery

34

Modify Internal Mail Servers

Changes are required to your existing internal mail server(s) to route outbound mail through the ePrism Email Security Appliance. You must configure your internal mail servers to use ePrism’s hostname or IP address for SMTP delivery of outbound mail.

This procedure depends on the type of internal mail server you are using. The following instructions are for a Microsoft® Exchange server.

Exchange 5.5

For Exchange 5.5 systems, use the following procedure:

1. Open Exchange Administrator.2. Go to Organization -> Site -> Configuration -> Connections -> Internet Mail Service

Properties.3. In the Connections tab, go to the Message Delivery section and in the dialog box Forward all

messages to host, enter the IP address of the ePrism, such as 192.168.1.128.

Exchange 2000

For Exchange 2000 systems, use the following procedure:

1. Open Exchange System Manager. 2. Go to Servers -> Exchange server name -> Protocols -> SMTP -> Default SMTP virtual

server -> Properties -> Delivery -> Advanced. 3. In the Smart host dialog box, enter the fully qualified domain name, such as mx1.example.com,

or IP address of the ePrism in brackets, such as:[192.168.1.128]

Page 37: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Starting Mail Services

Starting Mail ServicesWhen your ePrism system is configured with your required networking information and mail routes are defined, start the mail system from the Activity screen by clicking the Start button.

For more detailed information on how to configure ePrism’s powerful mail security features, please see the ePrism User Guide.

35

Page 38: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

Configuring Mail Delivery

36

Page 39: ePrism Installation Guide · 2016-10-03 · 3 Preface Preface This Installation Guide provides instructions on how to install and provide the initial configuration for the ePrism

CORPORATE ADDRESS15015 Avenue of ScienceSan Diego, CA 92128 USAToll Free: 800-782-3762Telephone: 858-676-2277Fax: 858-676-2299Email: [email protected]: www.stbernard.com

EUROPEAN ADDRESSUnit 4, Riverside WayWatchmoor Park, Camberley,Surrey GU15 3YQ, United KingdomTelephone: +44 (0) 1276-401640Support Telephone: +44 (0) 1276-401642Fax: +44 (0) 1276-684479Email: [email protected]

EPENT0805© 2004-2005 St. Bernard Software Inc. All rights reserved. The St. Bernard Software logo is a trademark of St. Bernard Software Inc. ePrism is a registered trademark of St. Bernard Software Inc.All other trademarks and registered trademarks are hereby acknowledged.

Protecting Your Network InvestmentProtecting Your Network Investment

WWW.STBERNARD.COM • 1-800-782-3762

ePrism Installation Guide

M 1 0 0 0 , M 2 0 0 0 , M 3 0 0 0SOFTWARE VERSION: 5.0LAST REVISION: 5/24/05