Trust G Suite in LibraCyber ESG
To trust Google G Suite and enable outbound mail relay, navigate to Admin Area > Mail Transport > Relay Configuration and select Trusted Networks. Click on the Enable button beside Trust Google Suite.
ESG Connector Configuration LibraCyber ESG offers native integration with G-Suite. To retrieve information such as users, groups, and email addresses from an Office 365 tenant you have to assign some permissions from your G-Suite tenant. To configure the integration you’ll need this credentials:
- OAuth2 Client ID and Client Secret: these are used to authenticate the users from the web interface
- Service account JSON configuration: this is used to fetch all the remote users and all the remote emails
- Your G-Suite Organization ID
To create the connector, Click Admin Area -> Integrations-> G Suite and then click New
| Domain | Select a specific domain to bind this connector to or select All Domains |
| Description | Enter a friendly description here |
| Client ID | Enter the Client ID created in Google API & Services |
| Client Secret | Enter the Client Secret generated by Google API & Services |
| Google Organization ID | Enter the ID of your GSuite Organization |
| Administrator email | Enter the email address of one of the G-Suite Administrator |
| Service Account Unique ID | Enter the ID of the Service Account you created to access your G-Suite instance |
| Service Account Email | Enter the email address of the Service Account you created to access your G-Suite instance |
| Private Key | Enter the Private Key from JSON File of the Service Account authentication token you created to access your G-Suite Organization |
Click Save Test your settings by clicking on the test icon next to your connection entry.
Add a relay to LibraCyber Email Security Gateway
To add a domain and forward clean emails to Google Apps, navigate to Admin Area > Mail Transport & Relay Configuration and select Domain Relay > New. Fill in the fields as follows:
- Domain: specify your domain, the one you have with Google Apps
- Mail Server: aspmx.l.google.com
- Port:: 25
- Use MX: NO.
- Recipient Verification: Dynamic Verification (or “Disabled” if you enabled a “catch-all address”)
- Dynamic Verification Server Address: aspmx.l.google.com
- Dynamic Verification Port: 25
- Domain Anti-spoofing set it to SPF.
Finally, remember to add the MX record with the highest priority (less weight) of your ESG appliance to route mail flow through LibraCyber ESG.
Import Users from G-Suite to ESG Appliance Click on Mail Transport->Recipient Verification->G-Suite Import Click the pencil sign to edit
In Enable Automatic Sync, check the box to allow automatic sync and click Save
In the Valid Recipient Verification page, click G-Suite Import. This will import all users in G-Suite mail server and it will auto sync every hour to import newly created users