Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Strange issue related to IP Aliases on a XG Firewall

I am experimenting the following issue:

We have a Firewall (free software based), protecting a LAN network. On this LAN there are four Email Servers, let’s call them server A, B, C and D, positioned in differents zones behind the firewall..
On WAN interface, each of these servers have its own Public IP assigned, to become published on internet; that means, there are four IP aliases defined in the WAN interface and each of them assigned to one of the email servers.

The main task is to replace this old firewall with a new Sophos XG 310 Firewall appliance, with the last firmware, v18.0.5 MR5 (Build 586). After configuring this new firewall, everything is working correctly, except one thing.., the mail servers cannot exchange messages between them. All of them can exchange messages with any mail server on internet (Gmail, Hotmail, other corporate email servers).., but for some reason, cannot exchange messages between them.

The problem is, that, the four email servers can exchange messages between each other (besides exchanging messages with any internet email server) only when using the old software based firewall.

We need help urgently, we spent the last three weeks trying to solve this issue, and just now I realize that looks like it is not a firewall rule or NAT rule problem, but must be something else in the appliance. We test two email servers today only to analize the problem, and we could see that one of them could send a meesage to the other, but this one cannot reply the message to the first one; , only gets a “timeout”.

I hope someone can help us.



This thread was automatically locked due to age.
Parents
  • If you have configured different zones for each Mail Server, you need Firewall Rules to allow the traffic between the zones.

  • Hi,

    Thanks for your suggestions..!..., there is not traffic between zones, the fact is that each mail server use the Alias IP assigned to connect other Email Servers out of the network. So, the connection happens out of WAN interface, and we are having problems with the connections at the same interface..., between IP Aliasses. My question is: it permitted in XG Sophos Firewall that two or more IP Aliases defined in one interface (in this case WAN) get connections between them?... that is the problem I have... 

Reply
  • Hi,

    Thanks for your suggestions..!..., there is not traffic between zones, the fact is that each mail server use the Alias IP assigned to connect other Email Servers out of the network. So, the connection happens out of WAN interface, and we are having problems with the connections at the same interface..., between IP Aliasses. My question is: it permitted in XG Sophos Firewall that two or more IP Aliases defined in one interface (in this case WAN) get connections between them?... that is the problem I have... 

Children
No Data