This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Email outbound Firewall business rules.

XG 210 enterprise protect.

 

Hi all, 

I've setup the above FW with minimal configuration and I'm looking for some support.

By default, I have the following Firewall rules. 

1. allow any any outbound,

2. allow Outbound email scanning (scan smtp, scan SMTPS)

i'm sure there are more fancy rules I need to setup, but I'll finish reading the config doc before I get to them.

 

Our email system is hosted on the internet. not on-premis.

 

The problem I have is that i have a number of applications / CRM intranets etc that are trying to send emails outbound and failing. 

When I try to telnet <smtp.server.ip> 25 it says "220 SOPHOS ESMTP" and nothing else works.

 

When looking at the SOPHOS logs, I can't see anything port 25 related attempting to go outbound, so it looks like my outbound port 25 requests are just stopping at the FW.

its worth noting at this point, all my users who have outlook setup as their email clients are sending / receiving emails fine. i guess because they are using IMAP.

 

what I've done is disable the FW rule that is checking the SMTP traffic and now it allows the traffic to flow out without any issues (but now its not being checked)

I've followed these instructions below to create a new rule, but made no difference.

https://community.sophos.com/kb/en-us/123663

 

Any suggestions that I can try to allow scanning of IMAP / SMTP outbound without blocking it?

 

Many thanks in advance and any pointers would be most appreciated!

Dave.

 



This thread was automatically locked due to age.
Parents Reply
  • By default the XG comes with MTA mode configured.  If you have not configured it, then change to "Legacy" mode.

    MTA mode will intercept all port 25 traffic and then send it on as a mail server.

    Your firewall rule of "any" to "any" on "any service" is not quite right.  You may have opened yourself up to attack or open proxy.

    Please read the documentation surrounding deployment of the XG.  If you still require help afterwards, log a support ticket.

     

    Thanks!

Children