This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Unable to block IP address.

Sophos SG210 Hardware

Sophos XG 17.5 GA Firmware

 

-----

This is both an Email Protection / Firewall Rule issue.

 

I am using my XG for email filtering inbound and outbound.  -- Email protection in MTA mode. (SMTP Relay enabled on WAN zone -- Port 25 is NOT in a DNAT.)

Exchange server uses XG as smart host. XG proxies all SMTP to and from Exchange.

XG ONLY allows relaying from EXCHANGE via internal IP.. Everything else attempting relay is blocked.

 

I have country blocking rules and IP blocking rules setup.

Very often, an attempt to relay mail off my exchange server is dropped.  

 

I've blocked the source IP but that still does not seem to have stopped the attacker from trying to relay.

 

I am very very familiar with XG and UTM (Certified Architect in both) so I am pretty confident that I have set this up correctly, but I am starting to have my doubts now. 

Looking for any kind of help / Ideas. 

 

Thanks!

 



This thread was automatically locked due to age.
Parents Reply Children
  • LuCar Toni said:
    You should check, whether you can relay now or not. 

    SMTP is kinda dangerous to configure, so be sure, everything works properly.

    Thanks I will double check and make sure I am not an open relay.

    rfcat_vk said:
    A word of warning, not all .ru sites are sourced from Russia, I found that some are sourced using US data centres.

    Ian

    Yes this is very true, there are several Russian customers in the data center I work in. I am also doing IP blocking not just country blocking, these relay attempts were coming from within the US, and I had explicitly blocked with a firewall rules, however the attempts kept coming through but getting denied.

    After making these changes the email logs no longer show any relay attempts, there is only the incoming and outgoing mail for the exchange server.

    Thanks again everyone