This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XT EMail Protection ... was mache ich falsch?

Hallo zusammen,

seit rund 10 Jahren setze ich bei mir und einigen Kunden die Sophos UTM ein. Kann also nicht unbedingt sagen,
dass ich im Firewall Bereich ein Anfänger bin.

Ich versuche seit rund einer Woche die E-Mail Security auf einer Sophos XG (Home Edition), die ich bei mir zuhause
verwenden möchte, einzurichten. Doch mir gelingt es einfach nicht, dass diese greift. Bei der bisherigen UTM war
es doch so, dass der Proxy den EMail Port SMTP oder POP3 abfängt und keine expliziten Firewall-Rules erforderlich
waren. Ich konnte also entweder von einem Exchange Server oder Mail Client über Port 25 eine Mail an die Firwall
senden und der SMTP Proxy hat diese entweder direkt oder mit Hilfe eines Smarthosts an einen Internet Server
weitergeleitet.

Bei POP3 war es ähnlich. Der Mailclient (z.B. Thunderbird) hat über die Firewall als Gateway eine Mail vin einem
Internet Mailserver geholt. Der POP3 Proxy hat gefiltert, Spam und Viren gesucht und die Mails zum Client durch-
geleitet.

Doch wie konfiguriere ich diese simple Funktionalität in der Sophos XG SFOS 17.5.8 MR-8? Wunsch wäre neben
POP3 auch IMAP  Zugriffe mit zu filtern. Die auf der Sophos Seite bereitgestellten 3 Dokumente gehen stets davon
aus, dass ein Mailserver per SMTP auch aus dem Internet Mails empfängt. Der einfache Fall, User setzt einen
Mailclient ein finde ich nirgendwo beschrieben. Gibt es hier ein HowTo oder kann mir von euch jemand den
entscheidenden Tip geben.

Problem ist, dass ich im Maillog nur die von der Firewall intern versendeten Mails (Error Logs, ALert Mils usw)
sehen kann. Aber ich müsste doch auch Mails von meinem Testrechner eingehend wie ausgehend geloggt
bekommen.

Meine Testkonfiguration:
Port 1 =  LAN Zone
Port 2 =  WAN Zone

Internet Mailserver mit einem Testpostfach erreichbar über IMAP und POP3, Internet Mailserver soll SMTP
Mails aus dem LAN weiterleiten (SMTP Replay Host).

Es ist klar, dass der Mailclient in der LAN Zone steht.

Was muss ich an Firewall Rules definieren? Im Moment sind die Regeln so definiert, wie nach der Werks-
einstellung. Der SMTP Deploy Mode muss doch auf "Device acts as a Mail Transfer Agent (MTA)." stehen.
Oder?

Vielen Dank im Voraus für eure hoffentlich zahlreichen und hilfreichen Beiträge.

Viele Grüße
Michael



This thread was automatically locked due to age.
Parents
  • Michael, 

    I will write in English as I do not speak German (when I was a child, my Deutsche was better than English). 

    On XG you have 3 modes to filter traffic:

    POP3 and IMAP proxy: https://community.sophos.com/kb/en-us/123274

    SMTP transparent proxy (on XG it is called legacy). SMTP traffic is intercepted and scanned automatically: www.sophos.com/.../Protect-Internal-Email-Server-.pdf

    and MTA mode: https://www.sophos.com/en-us/medialibrary/PDFs/documentation/SophosFirewall/Pocket-Guides/ProtectInternalEmailServerMTAMode.pdf?la=en where you need to configure XG to send email to your email servers and vice-versa.

    Regards

  • Important to know: XG does not have the same kind of POP3 Proxy like UTM. There is no "prefetch" option. 

     

    Most customers (XG is a business product) are not using IMAP / POP3 anymore (moved to O365 - SMTP MTA). 

     

    If you have a mail server, you would go with MTA Mode. Its the same kind of mechanism like on UTM. You build a MTA (SMTP Proxy), talk to the Proxy via Port 25 directly. 

     

    If you have a POP3/IMAP Client behind XG, you can scan transparent, like lferrara mentioned. Same for outbound SMTP, if you want to scan the Client to Server communication. 

  • Dear Luk, 
    Dear Lucar,

    thanks for your Informations. I will try it on the evening.

    I suppose, I had use the wrong EMail Protection Mode. I supposed I must use the MTA Mode. The transparent Mode was a little bit suspect, i know it from the UTM Web Proxy :-) and it was easy to configure but a little bit limited ...

    More about the EMail Protection:
    Of course, the Customer use an Exchange Server but the company's are really small ones. We prefer to use an Internet Mailserver with some Mailboxes on Provider Side. Nearbe all of our customers use a DSL Internet Connection and it is possible that the Line is down. A Mailbox on Provider Side has the advantage that the Mail are received.

    On Severside a POP3 Downloader is active. This Service transfer periodically the Mailboxes every xx Minutes to the Exchange Mailboxes. It's also possible that few user use IMAP / POP3 Clients in the same Company to get access of other ISP Mailboxes (except these one for Exchange) on Mobilephone Devices or Windows Clients like Outlook or Thunderbird.

    By this way, is the legacy Mode the right Mode for this? Of course the XG POP3 Proxy hassn't a Prefetch Mode. But can i see all Mails (Incoming by POP3/IMAP or Outgoiung by SMTP) in the Mail Log of EMail Protection?

    Thanks!

    Michael

  • Michael,

    for legacy, you can scan SMTP traffic like transparent mode in UTM (more or less).

    Pay attention for IMAP and POP3 traffic. You cannot avoid spam email but you can just change the subject of each email, if the email is a SPAM email.

    https://ideas.sophos.com/forums/330219-xg-firewall/suggestions/10614834-pop3-imap-more-scanning-option

    Regards

  • Hi Luk,

    that sounds not good and I'm a little bit irritated :-)

    Whats the right Mode for my Problem or better to say if I want the XG Firewall like the UTM Firewall

    UTM with activated POP3 Proxy (Spam Quarataine, Spam E-Mail to Firewall Users to release or delete Spam) ...

    UTM with deactivated SMTP Proxy to send directly SMTP Mails to Internet Mail Server (ISP).
    UTM with activated SMTP Proxy to receive Outgoing Mails on XG Firewall, check Spam, Virus and send it to Internet Mailserver (ISP) by SmartHost.

    By this way: Is it possible to configure this? Or has the XG Firewall an other concept to protect E-Mails?

    Regards
    Micael

Reply
  • Hi Luk,

    that sounds not good and I'm a little bit irritated :-)

    Whats the right Mode for my Problem or better to say if I want the XG Firewall like the UTM Firewall

    UTM with activated POP3 Proxy (Spam Quarataine, Spam E-Mail to Firewall Users to release or delete Spam) ...

    UTM with deactivated SMTP Proxy to send directly SMTP Mails to Internet Mail Server (ISP).
    UTM with activated SMTP Proxy to receive Outgoing Mails on XG Firewall, check Spam, Virus and send it to Internet Mailserver (ISP) by SmartHost.

    By this way: Is it possible to configure this? Or has the XG Firewall an other concept to protect E-Mails?

    Regards
    Micael

Children
  • XG can scan and remove SPAM email only on SMTP protocol. Legacy == no email server relay to be configured. XG is transparent, intercept the request, remove the spam, and the traffic flow proceeds.

    MTA: you need to configure email relay on exchange server to and from. Same thing for ISP or external server (if your XG does not send email directly to internet).

    Regards