Although users do not access the domain as they use the GroupWise client, their messages often pass through domains while traveling from one post office to another.
You can configure the MTA to restrict the size of messages that users are permitted to send outside the domain.
In ConsoleOne, click
.Double-click the domain where you want to restrict message size.
In the
field, specify in megabytes the size of the largest message you want users to be able to send outside the post office.If you want to delay large messages, specify the size in megabytes for message files the MTA can process immediately in the
field.If a message file exceeds the delay message size, the message file is moved into the low priority (6) message queue, where only one MTA thread is allocated to process very large messages. This arrangement allows typical messages to be processed promptly, while delaying large messages that exceed the specified size. The result is that large messages do not slow down processing of typical messages.
Click
.To exit the Link Configuration Tool and save your changes, click
.ConsoleOne then notifies the MTA to restart using the new message size limits.
If a user’s message is not sent out of the domain because of this restriction, the user receives an e-mail message providing the following information:
Delivery disallowed - Transfer limit is nn MB
However, the message is delivered to recipients in the sender’s own domain.
There are additional ways to restrict the size of messages that users can send, as described in Section 12.3.4, Restricting the Size of Messages That Users Can Send.
You can configure the MTA to redirect GroupWise Remote client requests to other MTAs and POAs. The GroupWise client can establish a client/server connection to an MTA across the Internet, eliminating the queuing and polling process used by earlier Remote clients. The result is significantly improved performance for Remote client users.
To configure the MTA to redirect Remote client requests, add the /liveremote, /lrconn and /lrwaitdata switches to the MTA startup file.
You can monitor the live remote connections from the MTA server console. See Displaying Live Remote Status.
As an alternative to live remote connections from outside your firewall, you could set up proxy servers for the POAs, so that client users in Remote mode connect to their mailboxes through the proxy servers rather than through MTAs. Full SSL security is provided through the proxy servers. See Section 36.3.1, Securing Client/Server Access through a Proxy Server.
Secure Sockets Layer (SSL) ensures secure communication between the MTA and other programs by encrypting the complete communication flow between the programs. For background information about SSL and how to set it up on your system, see Section 71.0, Encryption and Certificates.
To configure the MTA to use SSL:
In ConsoleOne, browse to and right-click the MTA object, then click
.Click
to display the Network Address page.To use SSL connections between the MTA and the POAs for its post offices, which provides optimum security, select
in the drop-down list.The MTA must use a TCP/IP connection to each POA in order to enable SSL for the connection. See Using TCP/IP Links between a Domain and its Post Offices.
Each POA must also have SSL enabled for the connection to be secure. See Section 36.3.3, Securing the Post Office with SSL Connections to the POA.
To use SSL connections between the MTA and the MTA Web console displayed in your Web browser, which provides optimum security, select
in the HTTP SSL drop-down list.To set up the MTA Web console, see Section 42.2.1, Setting Up the MTA Web Console.
Click
to save the settings on the Network Address page.Click
to display the SSL Settings page.For background information about certificate files and SSL key files, see Section 71.0, Encryption and Certificates.
In the
field, browse to and select the public certificate file provided to you by your CA.In the
field:Browse to and select your private key file.
Click
Provide the password that was used to encrypt the private key file when it was created.
Click
.Click
to save the SSL settings.ConsoleOne then notifies the MTA to restart using the new message size limits.
Corresponding Startup Switches You can also use the /certfile, /keyfile, /keypassword, /httpssl, and /msgtranssl switches in the MTA startup file to configure the MTA to use SSL.
MTA Web Console You can list which connections the MTA is using SSL for from the Links page. Click to display the list if TCP/IP links.