You must set the value to $true for the RequireTLS parameter when you enable Extended Protection Authentication and you expect ...

You must set the value to $true for the RequireTLS parameter when you enable Extended Protection Authentication and you expect clients to connect directly to this Receive connector using TLS. If your server is behind a firewall and TLS terminates at the firewall, set the value of the ExtendedProtectionTlsTerminatedAtProxy parameter to $true instead.