Cisco Cisco Email Security Appliance C190 User Guide

Page of 1094
 
36-25
Cisco AsyncOS 8.0.1 for Email User Guide
 
Chapter 36      Testing and Troubleshooting
  Troubleshooting Email Delivery From the Appliance
You can use the 
tlsverify
 command to establish an outbound TLS connection on demand and 
debug any TLS connection issues concerning a destination domain. To create the connection, 
specify the domain to verify against and the destination host. AsyncOS checks the TLS connection 
based on the Required (Verify) TLS setting.
Enter the remote hostname or IP.
[]> problemdomain.net
Enter the remote port.
[25]> 25
mail3.example.com> tlsverify
Enter the TLS domain to verify against:
[]> example.com
Enter the destination host to connect to.  Append the port (example.com:26) if you are 
not connecting on port 25:
[example.com]> mxe.example.com:25
Connecting to 1.1.1.1 on port 25.
Connected to 1.1.1.1 from interface 10.10.10.10.
Checking TLS connection.
TLS connection established: protocol TLSv1, cipher RC4-SHA.
Verifying peer certificate.
Verifying certificate common name mxe.example.com.
TLS certificate match mxe.example.com
TLS certificate verified.
TLS connection to 1.1.1.1 succeeded.