Hey Peter!
Around June of 2022 I was on a webinar presumably about Harmony Email protection and it of course was all cloud.
I asked a question and you graciously sent me this link, thank you so much!
I wonder if you may have updated that paper at any point, or if you think that it applies for the R81.10 environment as well?
One other thing we need to address in my environment is enabling TLS inspection and how to deal with the certificates.
We have this setup:
Internet --> CheckPoint 5200 GW --> Specific external IP Static Nat --> Network Rule SMTP HTTP HTTPS --> Exchange Server.
Currently all certificates are installed on the Exchange server and are based on the FQDN of the static NAT external IP address DNS hostname, plus the internal hostname and autodiscover etc.
I would like to enable the MTA and have it inspect SMTP TLS traffic. Searching the PDF for TLS only had a couple of hits, but I have not read the whole thing through yet. I am getting started on it now, and will search Check Mates and support KB for information about how to set that all up.
I have some stuff configured on our exchange server that FORCES TLS for certain connections which I also would need to be able to reproduce for compliance reasons with certain partner organizations.
Not really asking this info of you, just wanted to say thanks and put it into a post that I can come back to later.