To receive mail via TLS:
You will need to creat a Certificate Signing Request (CSR) on each Messaging Gateway that will be accepting mail via TLS. Purchase certificates from a Certificate Authority (CA). Then install the certificate and any intermediate certificates provided by the CA in the Symantec Messaging Gateway (SMG). Then once the certificate is installed you would select the certificate for use in inbound SMTP options for each host installed to.
Generation of a CSR and installation of certificates is done in Administration -> Certificates, installation of intermediate certificates is in the Certificate Authorty tab.
To set the MTA to accept message via TLS
Administration -> Configuration -> Select a host -> SMTP -> Inbound -> Check Accept TLS encryption, select the certificate for that host. Click Save.
To transmit using TLS:
You can tell Symantec Messaging Gateway to attempt to send via TLS for all messages in host delivery options.
Administration -> Configuration -> Select the host -> SMTP -> Advanced Settings -> Delivery -> Check Attempt TLS encrypteion for Delivery of all messages.
Click contiune then save.