Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall Traffic logs in depth

We have MS exchange servers hosted on our network and Firewall rules, Email filers and NAT configured on our Sophos XG to forward mail to our servers. Recently end users would have reported not receiving certain emails. This is random. After looking at the firewall email logs the mail appears to be sent, but it doesn't hit the user mailbox nor it shows up on the exchange log. I am trying to go deeper into the firewall logs to actually determine which NAT rule would have been used to specificaly determine which mail server it would have been forwarded to. Unfortunately, I can't figure it out or the Firewall doesn't give that kind of logs. I used multiple brands of firewalls and i know this can be done. 

Can the XG give that type of log?

How can i can i traverse my historical mail logs to determine which NAT rule was used or which mail server got the mail?

To note i have a NAT rule configured with multiple Exchange severs (port 25) with round robin selected has the decision maker.



This thread was automatically locked due to age.
Parents
  • Hi,

    in log viewer using the refined view of IP address that will show you the NAT rule used by that device. Further, select mail in log viewer then open one of the entries and that will show the firewall rule used by that email.

    Ian

    XG115W - v19.5.1 mr-1 - Home

    If a post solves your question please use the 'Verify Answer' button.

  • Thanks for reaching out.

    This helped but it only gave the NAT Rule ID. As i mentioned we have multiple MS exchange servers in that NAT rule that uses the round robin load balancing method. I want to determine which destination NAT IP that was used.

Reply Children