PDF(7.8 KB) View with Adobe Reader on a variety of devices
ePub(82.1 KB) View in various apps on iPhone, iPad, Android, Sony Reader, or Windows Phone
Mobi (Kindle)(67.5 KB) View on Kindle device or Kindle app on multiple devices
Updated:September 12, 2019
The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
This document provides information that might be required to configure a firewall and Cisco Email Security Appliance (ESA) for Cisco Registered Envelope Service (RES) communication to Cisco RES key servers. Customers with strict firewall rules require permissions for specific IP addresses or hostnames in order to allow communication for Cisco RES. Encryption via Cisco RES on the ESA requires firewall rules for port 80 and 443 in order to send key requests to Cisco RES to encrypt a message.
Cisco RES: IP Addresses and Hostnames for Key Servers
Cisco RES uses the following IP address ranges in order to initiate SMTP - Transport Layer Security (TLS) sessions:
Active (188.8.131.52 - 184.108.40.206)
Backup (220.127.116.11 - 18.104.22.168)
Some customers might restrict access to the Cisco RES key server res.cisco.com. The Cisco RES key server res.cisco.com has two (2) blocks of VIPs. Add them to your network device's access rules where appropriate:
Active (22.214.171.124 - 126.96.36.199)
Backup: (188.8.131.52 - 184.108.40.206)
Add the previously listed IP addresses and hostnames by their IP address range to your existing sender group that is used for TLS (Incoming):
Log in to the ESA GUI.
Navigate to Mail Policies > Host Access Table > HAT Overview and edit your TLS sender group (naming convention might vary).
Note: It is highly recommended to add the hostname .res.cisco.com along with the IP address range since any future additions will use the Domain Name Server (DNS) in order to do the lookup for the IP address information.
The previous Cisco RES key server hostnames might have been listed as: vega.res.cisco.com soma.res.cisco.com
It is recommended to update your network and/or firewall rules and definitions as well to match the previous information.