Installing applications on Microsoft Azure can be intimidating to those who have never used Azure. Thankfully, the LibraCyber ESG deployment process is very simple.
This article focuses on using the Microsoft Azure Marketplace to deploy a single instance of LibraCyber ESG and on what to expect during the installation.
Creating a LibraCyber ESG VM on Microsoft Azure
To begin with, you need a Microsoft Azure subscription.
- Login to Microsoft Azure portal at https://portal.azure.com and you should see your Azure Subscription
- Once logged, click on the Marketplace
This will take you to the Microsoft Azure Marketplace where you can search for products. Type in “Libraesva Email Security Gateway” in the search bar.
- Select the “LibraCyber Email Security Gateway” Template and click Create.
- Next, a basic configuration screen will show up. This is required for the installation process. You will need to create a new username and resource group first.
- Enter a descriptive name, choose the desired Region and Azure Availability zone and select “Password” as Authentication type.
- Select the VM size depending on your mail traffic (see this guide for general requirements indication: https://docs.libraesva.com/how-to/setup/libra-esva-technical-requirements/). We suggest using one of the following size:
- Leave all settings as suggested unless you know what you do. Click “Review + create”.
NOTE: When you create a Public IP make sure it’s a Static and not dynamic IP. If you chose dynamic IP Azure will assign a new public IP on every VM boot.
Disk Sizing
One you successfully deployed your VM, you need to stop it before you can edit disk configuration. The OS disk type and size should never be changed.
You could change the data disk type and size based on your requirements. LibraCyber ESG is a disk intensive application and requires at least 150 Mb/sec.
You can refer to the official Azure documentation. Be advised that Microsoft disks come in several fixed sizes, IOPS and throughput.
Ask Microsoft Support to open Outgoing SMTP
By default, Microsoft won’t allow sending and receiving traffic on port 25 for security reasons. Since Librasva ESG is an Email Gateway, it is not possible to work around this limitation, and port 25 is required to have a fully working appliance.
Access portal.azure.com and navigate to “Help + support -> New support request”, then fill in the form as in the image below:
Once you reach the detail page, set the severity to “moderate”, then write the following message:
We are integrating an Email Security Gateway, which should intercept all of our company's email and we also need to communicate with external mail servers.
It is not possible for us to use ports other than 25, as the SMTP for gateways strictly requires port 25 to be used, except in some special situations. We cannot provide a list of domains or IPs to limit the delivery, as we need to be able to send bounce emails back to any server which requires it.
All our outgoing emails will be encrypted with the use of TLS connections or STARTTLS connections, as long as the receiving server can process the request.
Once Microsoft agrees with the change, you may proceed to set up your appliance.
Setup Wizard and License
As soon as the machine has been deployed and powered up, please connect to the public IP address assigned and continue to run the usual LibraCyber ESG Configuration Wizard as described in the following guide, starting from point 2):
https://docs.libraesva.com/how-to/setup/
×NOTE: You need to purchase a valid LibraCyber ESG license to complete the installation Wizard, as the license model with Microsoft Azure is Bring Your License. Please contact sales@libraesva.com for any commercial needs.