Connection manager questions


We have due to security issues been forced to place our openfire server inside the firewall (Directory/LDAP lookups from DMZ not allowed). To allow external connections we have placed a connection manager in our DMZ. My first question, is it possible to force starttls in a connection manager ? Furthermore, is it possible to also route server to server communication through a connection manager or perhaps this is the wrong approach ?