This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG in MTA mode and 3 WAN-Interfaces ... unable to select the correct outbound interface

Hi,

configured XG 18.0.4 in MTA mode to send outgoing mail using a single interface.

But XG use another interface ...

i have 3 Gateways ... SMTP should use GW_WAN


Some hints where the error could be?

Thanks,

Dirk



This thread was automatically locked due to age.
Parents
  • Which Interface does the XG use? 

    __________________________________________________________________________________________________________________

  • DSL1


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • It uses the IP and the Interface or only the IP and the correct Interface? 

    Because you need NAT and SD-WAN PBR. 

    Maybe you need a Firewall Rule. Check if there is a MTA Rule. 

    __________________________________________________________________________________________________________________

  • It use the incorrect interface.

    i have the firewall-rules (and they matches while sending Mails)
    my configuration for SD-WAN PBR ist shown in the screenshot.
    i have a default-masq rule for all outgouing traffic/interfaces...


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • Hi  :  Please share some packets or information or snapshot where you are able to see incorrect Interface/IP for SMTP/SMTPS traffic.

    What is the status of SD WAN policy route for system generated traffic? 

    console> show routing sd-wan-policy-route system-generate-traffic

    Regards,

    Vishal Ranpariya
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link.

  • i see the false IP within mail-header of testmails.

    console> show routing sd-wan-policy-route system-generate-traffic               
    SD-WAN policy route is turned off for system-generated traffic. 

    should i enable this?
    set routing sd-wan-policy-route system-generate-traffic enable
     


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

Reply
  • i see the false IP within mail-header of testmails.

    console> show routing sd-wan-policy-route system-generate-traffic               
    SD-WAN policy route is turned off for system-generated traffic. 

    should i enable this?
    set routing sd-wan-policy-route system-generate-traffic enable
     


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

Children