This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Email Notification Error when hitting Test Mail button

Setting up our first XG unit (what a nightmare) compared to the SG units and ran into a pretty big problem.  Email notification will not work.  Put in the same Exchange Server we use for all of our SG units on port 587 with the same username/password and the same security.  No issues at all on our SG units, but on this XG we are getting this error:

 

"Authentication method mismatch.  Please confirm the authentication method support for LOGIN or PLAIN on the mail server"

 

We have verified all our information is correct and we can use telnet to connect with username/password provided without issue so it seems to be an issue with the actually XG software.  Please advice, we can NOT put this device in production without proper Notification setup.  Thank you



This thread was automatically locked due to age.
  • Hi Matt,

    Please post the screenshot of the configuration and the logs you see in the system > Diagonostics> log viewer section for test mail failure.

    Thanks

  • Like I said, same exact settings as we have on all of our UTM 9 SG units.

     

    Also....there has got to be an easier way to view the log files, using the log viewer most of the message is cut off and you have to "hover" to read the entire message.  How do you view in ascii format?

  • HI matt_ss, 

    Could you check by selecting SSL/TLS or StartTLS with appliance Certificate or without any certificate also the username used to establish the connection should be the same as From Email address. 

    If it does not work out then could you telnet from your system and share us the details . 

    Thanks and Regards

    Aditya Patel

  • The Username and From Email Address are the same.

     

    With Connection Security set to STARTTLS with NO certificate get this error:

    "Authentication method mismatch.  Please confirm the authentication method support for LOGIN or PLAIN on the mail server"

     

    With Connection Security set to STARTTLS with ApplianceCertificate get this error:

    "Authentication method mismatch.  Please confirm the authentication method support for LOGIN or PLAIN on the mail server"

     

    With Connection Security set to  SSL/TLS with NO certificate get this error:

    "Failed to connect to mail server.  For more information please check the log viewer"

     

    With Connection Security set to  SSL/TLS with ApplianceCertificate get this error:

    "Failed to connect to mail server.  For more information please check the log viewer"

     

    Again, this authentication works on all our SG UTM devices:

  • Hi Matt,

    Refer the document here. Verify on which port is the Telnet successful. I think that changing the port and taking the above four permutational steps will resolve the issue.

    Hope that helps.

  • Still didn't resolve the issue.  I was able to setup a XRelay for our hosted exchange server that as long as we are sending internal doesn't require authentication.  Was able to get the sophos to send out email as long as authentication wasn't enable.  Using telnet the issue seems to be with the sophos software not being able to send authentication correctly especially NTLM.  How do all these "bugs" make into a production version of the software, you would think these things would be worked out in BETA.  I guess we will wait until Sophos has this Authentication issue resolved before we can start using port 587 with authentication.  What is an ETA on this resolution?????

  • HI matt_ss, 

    Could you log a case with Support and Private message me the case ID . So I may monitor the case . 

    Thanks and Regards

    Aditya Patel | Network and Security Engineer.

  • Hi Matt

    May I know how do you fix the issue ?

    I have the same issue with XG (ver 17.0) currently.

    Thank so much

  • Gecko - 

     

    Never did actually get this fixed.  This was the ONE and only XG until we ever tried to deploy.  It is no longer in LIVE environment.  At this point, we only deploy SG UTM units.