This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Outlook 2010 client not able to connect to provider

Hello to all,
 
Situation:
I have an outlook client (2010) in the internal network that has to connect to an external e-mail provider to send and fetch e-mail.
The Sophos XG is in transparent Mail delivery mode (not MTA).

I have a business application rule in place that scans traffic: imap/imaps/pop/pops/smtp/smtps (the services to scan are predefined and can be selected by checkbos).
 
Until now the e-mail provider delivers mail still unencryptet, so POP = 110, SMTP = 25 and everything is working fine: the outlook client connects to the e-mail provider, send and receive e-mail is no problem.
 
 
By end of this month the provider will switch to encryptet mail and turn off unencryptet protocols:
POP will be POPS = 995
SMTP will be switched to SMTPS = 465
 
The problem is: whenever I change the outlook client settings, the client is not able to connect to the provider anymore.
 
I tried to implement different network and also business application rules that would allow the client to pass on the given ports (995/465), but nothing I tried is working.
Please help!


This thread was automatically locked due to age.
Parents
  • Hi,

    Have you installed the CA on each device?

    Also the XG does not currently recognise 587 as SMTPs only 465, I am hoping the MR-6 will add 587 the mail business rule SMTPS ports.

    Ian

     

    Edit : corrected wrong port information.

  • Yes, CA is installed on each device.

    Wow... XG does not support 465? That is absolutely nogo..! The provider is changing per end of June, I have to make this work....

  • Hello Ian

    Thank you for testing and your input! meanwhile I did some further tests with a different mail client program, test szenario and outcome:

    Szenario 1

    Mail client installation

    • installation of Thunderbird as e-mail client program
    • import of XG SSL certificate into Thunderbird

     

    Configuration of thunderbird same as in Outlook 2010:

    pop server: pop3s.bluewin.ch port 995

    smtp server: smtpauths.bluewin.ch port 465

     

    Test pop/smtp connectivity:

    -> works like a charm!

     

    Szenario 2

    Mail client installation

    • installation of Outlook 2010 as e-mail client program
    • import of XG SSL certificate into the windows certificate trust store

     

    Configuration of Outlook:

    pop server: pop3s.bluewin.ch port 995

    smtp server: smtpauths.bluewin.ch port 465

     

    Test pop/smtp connectivity:

    --> No connection

    Sorry, windows is in german. Translated:

    "your server does not support the required connectivity encryption type. Try to change the connectivity encryption type or contact yourt system administrator or e-mail provider."

     

    Here my Sophos settings:

    1. Firewall business application rule

     

    2. E-Mail policies

     

    3. Mail general settings

     

    I have also an Outlook 2010 test client that is directly connected to the internet with exactly the same outlook configuration as inhouse:

    it works perfect!

     

    Is there any help on this please?

    I have no ideas anymore...

  • Hi Nicole,

    I can't see what your outlook configuration is, do you have use SSL enabled?

    When you open log viewer in the mail window and try to connect what errors do you see?

    Ian

  • Hi Ian

    The outlook configuration looks like this:

     

    I don't know what you mean by log viewer in the mail window? when I try to connect the connect window is open and delivers the error I have posted above.

    see again here:

  • Hi Nicole,

    on the XG using the logviewer you select mail from the menu.

    Also I have outlook 2016 run ning only wife's MBP using iMAPs and SMTPs and she can send and receive emails using a similar mail business rule to yours.

    Ian

  • Hi Ian

     

    thanks for replying again! I appreciate every help very much!

    after I've seen your post this morning I have completely re-installed the client host - setup from scratch with new windows 7 and office. but... no luck. it is not a failure in OS or office outlook, I get exactly the same errors as yesterday and before.

     

    I checked the mail log, but this stays empty.

    I checked "all logs" too. a lot of entries, but no block during the time I have tested the connectivity (see below). there were some country blocks 5 minutes ago, but disabling the rule showd, it is not related to my outlook errors.

    any ideas?

    the certificate is in the windows trusted store still - or yet, as I deploy it via group policy.

     

  • Hi Nicole,

    most of those entries are nothing to do with mail. There is one entry for mail using port 465 which has gone through.

    In logviewer when you click the email from the drop down menu you should see a report like this

    Please excuse the funny report, I am hoping there will be a fix in MR-6 that will stop this.

    You should see entries like queued for scanning, delivered etc.

    Also, probably a minor difference is I ticked disable legacy TLS.

    I have also found those mail policies very confusing, the SMTP policies appear to only apply to servers.

    The XG does not classify its own 465 mail as SMTPS even when it shows that in the menu of the administration notifications configuration.

    Ian

  • Hi Ian

     

    You are right, when I do not set any time filter, I can see mail logs.

     

    Situation: Outlook was closed when I stopped working last nicht at 3am something and just opened right 10 minutes ago, around 11:40.

    I opened the mail logs and saw all mails that arrived between 3am and 11:40am, last arrived at 11:39 exact time (-> see on the printscreen below, it was the same as it is after the test)

     

    1. I changed the outlook settings to SSL (same as described before)

    2. Tried to establish connection to the server -> test connectivity in outlook -> see below

    3. Receive the same error as always -> see below

    4. refreshing the mail logs -> no activity (of course not)

    (last entry is the same as I saw at 11:40 when the program was initially opened)

     

    5. Switched back the outlook settings to unencrypted -> Connection successful, Mail passes (11:46h)

     

    I am so **** ... what is blocking me from beeing able to connect...???

  • Hi Nicole,

    I know this is not much help to you. Getting mail to work correctly took me some time, I could get Mac mail or outlook but not both. After much trial and error and a number of software updates from both MS and Sophos I have my wife's Mac mail and outlook actually agreeing to the amount of messages.

    At this stage I will have wait until one of the more experienced XG support people review your issues.

    Regards

     

    Ian

  • Hi Ian

    Thank you for your reply!

    Can you please tell me what is happening now?

    Is someone of the more experienced XG support people reviewing my issue automatically or can I just wait and hope that probably someone looks at it? Or maybe never will...?

     

    Thank you for short answer!

    Thank you for all the time and effort you took for me!

     

    Best regards

    Nikki

     

     

     

     

  • Hi Nicole,

    if you want a quicker fix than relying on the forums you need to log a support case.

    Ian

Reply Children
  • I fixed the SSL issue.
    I am a little bit surprised that obviously no other user ever ran into that issue.... and first of all let me say: the issue has not been caused by Sophos.
    The issue has been Windows 7.:
     
    Windows 7 does not natively support TLS 1.1 and TLS 1.2
    I had to tune the registry of Win7 so TLS 1.1 and TLS 1.2 are working.