Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive Administrator's Guide - Kerio Software Archive
from More from this publisher

Chapter 6 Services• SMTP on port 25 with STARTTLS — traffic on port 25 is started as unencrypted. Ifboth sides support TLS, TLS is started via STARTTLS. Otherwise, the traffic is heldunencrypted.• SMTP with SSL/TLS on port 465 — the traffic is encrypted right from the start.Warning: If traffic between Kerio MailServer and mail client is running on port 25, a problemmight occur with email sending. Since public WiFi networks often do not supporttraffic on unencrypted protocols, SMTP on port 25 can be blocked. In such case userscannot send email out of the network. However, SMTPS on port 465 is usually allowed.Therefore, it is recommended to keep SMTPS connection enabled so that notebook andApple iPhone users can use this port to connect to the server. It is also necessary thatusers’ email clients (SMTPS encryption and traffic port) are set correctly.POP3POP3 protocol server (Post Office Protocol). This server allows users — clients to retrievemessages from their accounts. It is also often referred to as the incoming mail server.Secure POP3 is a POP3 server whose communication is encrypted by SSL. The encryptionprevents the communication from being tapped.IMAPIMAP protocol server (Internet Message Access Protocol). This server also allows users toaccess their messages. With this protocol, messages stay in folders and can be accessedfrom multiple locations at any given time.Secure IMAP is an IMAP server whose communication is encrypted by SSL.NNTPNNTP protocol (News Network Transfer Protocol) — transfer protocol for newsgroupsover the Internet. The service allows users use messages of the news type and use theprotocol to view public folders.Public folders cannot be viewed via NNTP protocol if its name include a blank space orthe . sign (dot).Secure NNTP is the NNTP server version whose communication is encrypted by SSL.LDAPSimple LDAP server that enables users to access centrally managed contacts. The LDAPserver provides read-only access to the information; you are not allowed to create noredit the existing ones.Secure LDAP is an LDAP server whose communication is encrypted by SSL.If Kerio MailServer is installed on a server which is used as a domain controller (in ActiveDirectory), it is necessary to run LDAP and LDAPS services on a non-standard port or todisable them.HTTPThe HTTP protocol is used for:1TLS is follower of the SSL protocol, it is actually SSL version 3.156

6.1 Service Parameter Settings• accessing user mailboxes via Kerio WebMail,• accessing the user administration via the KMS Web Administration interface (see chapter31),• accessing mail using Microsoft Entourage mail client (see chapter 38),• accessing the Free/Busy server,• automatic upgrades of new versions of the Kerio Outlook Connector and the KerioOutlook Connector (Offline Edition).• for synchronization via Kerio Synchronization Plug-in.• for synchronization via the ActiveSync protocol.• for BlackBerry synchronization via NotifyLink.• for publishing of calendars as iCalSecure HTTP is an encrypted version of this protocol (HTTPS — SSL or TLS encrypted).Upon the first startup of Kerio MailServer, all the services listed above are running on theirdefault (standard) ports.Note: If you know that services will not be used, it is recommended to disable them (forsecurity reasons).If any service provided also by Kerio MailServer is already running on the server, it is necessaryto change traffic port for one of the services. To change a port of a Kerio MailServer’s service,follow the instructions in section Service Parameter SettingsThe service list (see figure 6.1) includes the following information:• Service — includes protocol name and an icon informing whether the service is running orstopped.• Status (running/stopped) — this item shows whether the service is running or stopped.• Startup (Manual/Automatic) — information whether Kerio MailServer is started automaticallyor it must be run manually upon its restart.• IP addresses — this item shows all IP addresses and ports used for traffic by the particularKerio MailServer’s service.• Limit Access — Kerio MailServer allows narrowing access rights to a certain group of IPaddresses which will be allowed to use the particular service (usually, unsecured servicesare accessible from the local network only).The parameters of a selected service can be changed. To do this, use the Edit button. Thebutton opens the Service dialog (see figure 6.2). The dialog consists of the following tabs:FeaturesThis tab allows setting of startup type and of a TCP port for traffic.57

Chapter 6 Services• SMTP on port 25 with STARTTLS — traffic on port 25 is started as unencrypted. Ifboth sides support TLS, TLS is started via STARTTLS. Otherwise, the traffic is heldunencrypted.• SMTP with SSL/TLS on port 465 — the traffic is encrypted right from the start.Warning: If traffic between <strong>Kerio</strong> MailServer and mail client is running on port 25, a problemmight occur with email sending. Since public WiFi networks often do not supporttraffic on unencrypted protocols, SMTP on port 25 can be blocked. In such case userscannot send email out of the network. However, SMTPS on port 465 is usually allowed.Therefore, it is recommended to keep SMTPS connection enabled so that notebook andApple iPhone users can use this port to connect to the server. It is also necessary thatusers’ email clients (SMTPS encryption and traffic port) are set correctly.POP3POP3 protocol server (Post Office Protocol). This server allows users — clients to retrievemessages from their accounts. It is also often referred to as the incoming mail server.Secure POP3 is a POP3 server whose communication is encrypted by SSL. The encryptionprevents the communication from being tapped.IMAPIMAP protocol server (Internet Message Access Protocol). This server also allows users toaccess their messages. With this protocol, messages stay in folders and can be accessedfrom multiple locations at any given time.Secure IMAP is an IMAP server whose communication is encrypted by SSL.NNTPNNTP protocol (News Network Transfer Protocol) — transfer protocol for newsgroupsover the Internet. The service allows users use messages of the news type and use theprotocol to view public folders.Public folders cannot be viewed via NNTP protocol if its name include a blank space orthe . sign (dot).Secure NNTP is the NNTP server version whose communication is encrypted by SSL.LDAPSimple LDAP server that enables users to access centrally managed contacts. The LDAPserver provides read-only access to the information; you are not allowed to create noredit the existing ones.Secure LDAP is an LDAP server whose communication is encrypted by SSL.If <strong>Kerio</strong> MailServer is installed on a server which is used as a domain controller (in ActiveDirectory), it is necessary to run LDAP and LDAPS services on a non-standard port or todisable them.HTTPThe HTTP protocol is used for:1TLS is follower of the SSL protocol, it is actually SSL version 3.156

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!