π FTAPI Gateway: Implementation Appointment Checklist
Introduction
To successfully complete the implementation within the planned timeframe, the following points must be clarified and prepared in advance. Depending on the scenario selected in the implementation wizard, there are different requirements, which are explained in this article.
Step 1: The Questionnaire β
Before we start the appointment, we need technical details about your infrastructure.
β¬ Submit your data: Fill out the Questionnaire (SecuForm) at least 72 hours before our appointment. Without this data, we cannot prepare the configuration.
Step 2: Roles required during the appointment β
Depending on the scenario selected in the implementation wizard, there are different requirements, which are explained in this article.
Scenario A: Mailserver (Cloud or On-Prem) with upstream Gateway (Option A1)
Who needs to attend the appointment? (Roles)
- β¬ Mailserver-Admin: Must be able to create connectors and transport rules in Exchange Online / M365 or your on-prem system.
- Testing: For testing, it is necessary to define an outbound rule that does not initially route the entire mailflow to FTAPI. This can be configured via specific triggers such as a word in the mail subject or specific recipient domains.
- β¬ Security Gateway-Admin: Must be able to adjust routing on your gateway (e.g., Hornetsecurity, Sophos, Barracuda).
- Outbound: The security gateway must be configured to accept email from FTAPI.
- Inbound: The security gateway must be configured to forward emails to FTAPI. If desired, this can also be restricted to specific emails based on characteristics in the mail header. It is necessary to check in advance whether the security gateway is capable of this.
- β¬ Network/Firewall-Admin: (If a firewall is in the mailflow) Must be able to perform port releases (SMTP Port 25/587) and DNS adjustments live.
Scenario A: Mailserver (Cloud or On-Prem) with upstream Gateway (Option A2)
Who needs to attend the appointment? (Roles)
- β¬ Mailserver-Admin: Must be able to create connectors and transport rules in Exchange Online / M365 or your on-prem system.
- β¬ Security Gateway-Admin: Must be able to adjust routing on your gateway (e.g., Hornetsecurity, Sophos, Barracuda).
- Outbound: The security gateway must be configured to accept email from FTAPI.
- Inbound: The security gateway must be configured to forward emails to FTAPI and recognize based on specific details (e.g., the mail header) whether the email has already been at FTAPI, so that no loop is created between the security gateway and FTAPI. It is necessary to check in advance whether the security gateway is capable of this.
- β¬ Network/Firewall-Admin: Must be able to perform port releases (SMTP Port 25/587) and DNS adjustments live.
Scenario B: Standalone Cloud-Mailserver without upstream Gateway
Who needs to attend the appointment? (Roles)
- β¬ Mailserver-Admin: Access to Exchange / M365 to set up connectors and rules.
Step 3: Only for On-Premise operation
If you operate the FTAPI solution in your own data center:
β¬ Provision VM: Set up a VM with the latest build of AlmaLinux 9 (Min. 2 vCPU, 8 GB RAM, 10 GB HDD).
β¬ Check connectivity: Ensure that the VM can reach the mailserver and the gateway via the network.
β¬ SSL certificate is provided: Ensure that a valid SSL certificate is available for the FQDN of the gateway. If you want to use Let's Encrypt (ACME), port 80 (TCP) must be reachable inbound from the internet. For automated renewal, this port must be opened every 90 days (or permanently).