exchange publishing using tls1.2

eg1995 1,131 Reputation points
2020-11-09T13:40:49.787+00:00

Dears,

i have exchange servers 2016 published on cisco firewall.
TLS 1.2 was enabled on the firewall and then all email traffic stopped working.
how can i check TLS from server side and how can we make it use TLS 1.2 and disable the old one.
Thanks,

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,360 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Andy David - MVP 142.3K Reputation points MVP
    2020-11-09T14:40:52.253+00:00

    Unless you messed with something, you are already using TLS 1.2 for SMTP traffic with Exchange 2016.
    You can verify this very easily in the message headers or SMTP protocol logs.

    https://techcommunity.microsoft.com/t5/exchange-team-blog/exchange-server-tls-guidance-part-2-enabling-tls-1-2-and/ba-p/607761

    38338-image.png

    For other clients, follow the steps in those docs starting here:

    https://techcommunity.microsoft.com/t5/exchange-team-blog/exchange-server-tls-guidance-part-1-getting-ready-for-tls-1-2/ba-p/607649

    NO need to change anything on the firewall in that regard.

    1 person found this answer helpful.
    0 comments No comments

  2. Yuki Sun-MSFT 40,871 Reputation points
    2020-11-10T05:32:44.04+00:00

    Hi @eg1995 ,

    how can i check TLS from server side and how can we make it use TLS 1.2 and disable the old one.

    To validate whether TLS 1.2 is in use, agree with Andy that you can check the Message header or SMTP Logging. To analyze the message header, it's suggested to use the Message Header Analyzer at https://testconnectivity.microsoft.com. As regards to the protocol logging, you can enable the protocol logging on specific connectors and check if the following string exists:

    When the server is the SMTP receiving system:

    • TLS protocol SP_PROT_TLS1_2_SERVER

    When the server is the SMTP sending system:

    • TLS protocol SP_PROT-TLS1_2_CLIENT

    Regarding disabling the old one, please make sure you have completed the steps outlined in the two blogs shared above by Andy( Part 1: Getting Ready for TLS 1.2 and Part 2: Enabling TLS 1.2 and Identifying Clients Not Using It), then you can proceed to turn off TLS 1.0/1.1 by referring to Exchange Server TLS guidance Part 3: Turning Off TLS 1.0/1.1.


    If an Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.