Configuring the Security Gateway as a Mail Transfer Agent

You can configure the Security GatewayClosed Dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources. / ClusterClosed Two or more Security Gateways that work together in a redundant configuration - High Availability, or Load Sharing. as a Mail Transfer AgentClosed Feature on a Security Gateway that intercepts SMTP traffic and forwards it to the applicable inspection component. Acronym: MTA. (MTA) to manage SMTP traffic.

When a Security Gateway scans SMTP traffic, sometimes the email client is not able to keep the connection open for the time that is necessary to handle the email. In such cases, there is a timeout for the email.

MTA prevents this problem. The MTA first accepts the email from the previous hop, does the necessary actions on the email, and then relays the email to the next hop.

The MTA scans SMTP/TLS encrypted traffic for the supported Software Blades.

Notes:

Enabling Mail Transfer Agent

Disabling Mail Transfer Agent

Note - If the MTA queue is not empty, or if you disable the MTA first, it is possible to lose emails that are sent to the network.

  1. Change the network settings to stop sending SMTP traffic from external networks to the Security Gateway.

  2. Disable the MTA in the Security Gateway object.

Deploying MTA in Backward Compatibility Mode

You can use the Check Point MTA to only monitor SMTP traffic - only scan the emails, but not to forward them to the mail server.

Note - Make sure that the mail relay on the network can send a copy of the emails to the Check Point MTA.

MTA Engine Updates

The Mail Transfer Agent Engine Update is an accumulation of new features and bug fixes to the MTA engine.

MTA updates are available for Security Gateways R80.20 and higher, and R80.10 with the R80.10 Jumbo Hotfix Accumulator Take 142 (and higher).

It is delivered in the form of a CPUSEClosed Check Point Upgrade Service Engine for Gaia Operating System. With CPUSE, you can automatically update Check Point products for the Gaia OS, and the Gaia OS itself. For details, see sk92449. package and can be installed and upgraded manually through the CPUSE .The cpstop/cpstart or reboot are not required.

The updates do not conflict with the regular Jumbo HotfixClosed Software package installed on top of the current software version to fix a wrong or undesired behavior, and to add a new behavior. Accumulators and can be installed independently.

For more information about the MTA engine updates, see sk123174.

To check the current version of Mail Transfer Agent Update, run this command in the Expert mode on the Security Gateway:

cat $FWDIR/conf/mta_ver

Monitoring MTA

There are three views for MTA monitoring in SmartView available for Security Gateways R80.20 and higher, and R80.10 with R80.10 Jumbo Hotfix Accumulator Take 142 (and higher).