This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SPX Encryption Port

Hi. Ive configurated SPX Encryption with correct certificates and it works fine. Iam using a non standard port but my mails will be blocked if I send a SPX encrypted mail to a company with closed ports. Is it possible to change the SPX port to 443 and using utm webserver (autodiscover, owa ports) parallel with port 443. Maybe by using two different interfaces with dsl connections and different public IPs and vlan or something like that?

Kind regards.

Christian



This thread was automatically locked due to age.
Parents
  • Have you tried?   The interface clearly lets you choose both IP address and port.   Obviously, tbe address needs to be different than any used for User Portal, SSL VPN, or 443-enabled WAF sites.

    Then, consider that the change will cause previously sent messages to lose reply capability.   Fortunately, it sounds like you are still in pilot phase, so disruption should be minimal.

Reply
  • Have you tried?   The interface clearly lets you choose both IP address and port.   Obviously, tbe address needs to be different than any used for User Portal, SSL VPN, or 443-enabled WAF sites.

    Then, consider that the change will cause previously sent messages to lose reply capability.   Fortunately, it sounds like you are still in pilot phase, so disruption should be minimal.

Children
  • I used a hostname which is not used on in any other app, server etc. When I try to change the port to 443 I get the note that I cant do this because port 443 is used for virtual webserver autodiscover.

  • The initial issue is the IP address, not the host name. Autodiscover sounds like a conflict with email autodiscover configuration.  If you do not have an unused external address, you are out of luck.

    Once you solve the IP problem, you will have a certificate problem.   You need to add tbe new host name to your user portal certificate (additional SAN) and you will need to publish the new host name in DNS to tie it to the new IP address.