This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG Inbound DNAT Rule Working Fine But XG Blocking Server Outbound

Hi all,

We're fairly new to Sophos XG but we have our firewall rules set up and working so far. However, I have created a DNAT rule for secure LDAP which is working well and I can see the traffic being forwarded to the internal server. However, the response from the server is not reaching the destination.

I know the XG is the problem because if I change the default gateway on the server to the old firewall it works fine. The DNAT rule is reflexsive so I would have thought the XG being a stateful firewall would allow the outbound traffic from the server but this is not the case.

Do I need to create a user / network rule for the server for the outbound traffic?

Thanks in advance.

Lee



This thread was automatically locked due to age.
  • Hi,

    Just wondering: Are there outgoing packets on Port 2 with your external IP? 

  • Hi,

    Yes I can see outgoing packets on port 2 with our external IP for port 636.

    Thanks

  • Hi,

    Just wanted to post a final update on this in case anyone else has a similar issue. After checking the Mimecast portal I could see that the connection was working. For some strange reason the scheduled sync from Mimecast using LDAPS on port 636 was working but when I test the connection it is saying connection failed and pointing to a certificate issue. This is basically misleading as the daily scheduled sync works fine.

    Essentially the inbound DNAT rule suggested resolved the issue. I have let Mimecast know that their testing function does not seem to work correctly.

    Thanks for the help with this!

    Lee