Mail relay
Figure 7: Appliance in explicit proxy configuration in a DMZ
If you have a mail relay already set up in your DMZ, you can replace the relay with the appliance.
To use your existing firewall policies, give the appliance the same IP address as the mail relay.
Mail gateway
SMTP does not provide methods to encrypt mail messages — you can use Transport Layer
Security (TLS) to encrypt the link, but not the mail messages. As a result, some companies do
not allow such traffic on their internal network. To overcome this, they often use a proprietary
mail gateway, such as Lotus Notes
®
or Microsoft
®
Exchange, to encrypt the mail traffic before
it reaches the internal network.
To implement a DMZ configuration using a proprietary mail gateway, add the appliance to the
DMZ on the SMTP side of the gateway.
Figure 8: Protecting a mail gateway in DMZ
In this situation, configure:
Pre-installation
Deployment Strategies for Using the Appliance in a DMZ
McAfee Email and Web Security Appliance 5.1 Installation Guide
16