This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Close port 25 for MTA

I've got a customer with an XG310 firmware 18.5.1.

They have the MTA fully in use but they like to have there mail delivered on port 587. So i changed the auto added firewall rule, and that is working well.

Mail is coming from there antispam provider on port 587 and processed by the MTA successfully.

Now the customer wants to close down port 25 completely, so I removed SMTP service from the firewall rule, and everything is still working fine.

But I still can connect to port 25 from everywhere in the world. It won't let deliver mail on the port but I still can connect to it and do some commands.

Also a general drop or reject rule for smtp on top the firewall rules don't change that.

The latest i can confirm with my one company firewall, cannot block access from unwanted regions to smtp MTA.

Does anyone know where to start with this?

Thanks,



This thread was automatically locked due to age.
Parents
  • Is the XG connected to the internet directly or is there a modem in front of the XG?

     
    SFVH (SFOS 19.5.1 MR-1-Build278)  - Last (re)boot on Februari 20 2023
    Asus H410i-plus - Pentium 6605 Gold - 250GB M.2 PCIe NVMe SSD - 8GB - 3 ports
    [If any of my posts are helpful to you please use the 'Verify Answer' link]
  • Hi,

    you would need to build DNAT directing port 25 to a dead-end address, but even then I am not 100% sure that will catch all because port 25 is a XG system port which from memory sees all traffic before the traffic is passed to the firewall rules.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • Hi,

    you would need to build DNAT directing port 25 to a dead-end address, but even then I am not 100% sure that will catch all because port 25 is a XG system port which from memory sees all traffic before the traffic is passed to the firewall rules.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

Children