🔒 New browser security hardening is live to help defend against AI-driven attacks. Learn more

Configure SCG for Proofpoint

Prev Next

This document describes the steps to create a profile and routing rules in Proofpoint for eShare Secure Collaboration Gateway. At a high level, the steps involved are:

Outbound Rules: Proofpoint to eShare

Note: This is only a sample Email Firewall Rule. The Rules to be created in your tenant may vary depending on your requirements and use cases you intend to support with eShare.  

  1. Login to the Proofpoint Admin Center (https://protect.proofpoint.com) and navigate to ‘Email Protection‘ > ‘Email Firewall‘ > ‘Rules‘, then select ‘Add Rule‘.

  1. Input a unique, identifiable name in the ‘ID‘ field and add a ‘Description‘. Click on ‘Add Condition‘.

  1. In the ‘Add Condition‘ dialogue box, input the following:

    1. Condition: Message Headers

    2. Header: User Defined

    3. Header Value: esharesmg

    4. Operator: Equals

    5. Value: [secure-email]

When done select ‘Add Condition‘ to save your settings.

  1. Change the delivery route to ‘Re-route‘. Click on ‘Create SMTP Profile…‘ button to create a new Profile.

  1. In the ‘Add Profile‘ window, input the following:

    1. ID: Unique name for SMTP Profile

    2. Description: as desired

    3. Profile Type: Buffer Queue

    4. Host: IP/FQDN provided to you by eShare

    5. Delivery Type: Load Balanced

    6. Port: 25

    7. Timeout: leave blank

    8. From Address: SCG_no-reply@yourdomain.com

    9. Display Name: leave blank

    10. HELO Domain: Your domain

    11. SMTP Address: Use Original Recipient Address

Leave the other fields blank and save the profile.

Graphical user interface, application, Word  Description automatically generated

  1. Confirm the newly created SMTP Profile is selected. Enable ‘Stop other rules…‘ and select ‘Stop further rule evaluation and execution‘ under ‘Disposition Action‘. Save your Rule.

Inbound Rules: eShare to Proofpoint

NOTE:

Inbound Rules are recommended when you desire to capture email replies to eShare Secure Mails from external recipients that are sent directly from their native mail client and messages included in such replies are to be added to Secure Conversations in Trusted Shares. This rule is not required for replies posted by internal or external recipients in your eShare Web Portal.

  1. Navigate to ‘Email Protection‘ > ‘Email Firewall‘ > ‘Rules‘, then select ‘Add Rule‘.

  2. Input a unique, identifiable name in the ‘ID‘ field and add a ‘Description‘. Click on  ‘Add Condition‘.

  1. In the ‘Add Condition‘ dialogue box, Input the following:

    1. Condition: Message Headers

    2. Header: User Defined

    3. Header Value: references

    4. Operator: Equals

    5. Value: eflsmg

When done select ‘Add Condition‘ to save your settings

Graphical user interface, application  Description automatically generated

  1. Enable checkbox for ‘Change message headers…‘ and click ‘Add…‘ to add a new message header. Input the following values and save:

    1. Header: User Defined

    2. Header Value: x-smg-external-reply

    3. Operator: Equals

    4. Value: external_reply

  2. Enable checkbox for ‘Send a copy to destination…‘ Select the ‘Copy filtered message‘ option. Select ‘New recipient(s)‘ and input cloneemail@somedomain.com. Save the rule.

  1. Next, create a new Email Firewall Rule to route the email clone from the above steps to eShare Secure Collaboration Gateway. Input a Unique name in the ‘ID‘ Field and a ‘Description‘. Click on ‘Add Condition‘. In the ‘Add Condition‘ dialogue box input the following:

    1. Condition: Envelope Recipient Email Address

    2. Operator: Equals

    3. Value: cloneemail@somedomain.com

When done select ‘Add Condition‘ to save your settings. Select ‘eShare‘ for the ‘SMTP Profile‘. Enable ‘Stop other rules…‘ and select ‘Stop further rule evaluation and execution‘ under ‘Disposition Action‘. Save your Rule.