Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

What is the "Auto added firewall policy for MTA"?

Dear Sir,

After switch email protect to MTA mode, 
the XG create the "Auto added firewall policy for MTA" automatically.



But the KB mentions as following,
No firewall rule/business application rule is needed to allow inbound emails in MTA mode
No firewall rule/business application rule is needed to allow the outbound emails in MTA mode.

https://community.sophos.com/kb/en-us/125596

Since no firewall rule/business application rule is needed, why XG create the rule automatically?

What is the rule used for?

Thanks~



This thread was automatically locked due to age.
Parents
  • Shuze,

    the rule is created automatically once you enable the MTA mode on Email Protection. Firewall rule is needed otherwise traffic is dropped. Try to disable the rule and see that traffic will be dropped.

    I do not why the KB says that. Maybe they consider the fact that the rule is automatically created by the XG.

    Let us know.

    Regards,

  • The firewall rules isn't needed in MTA mode but the to-the-box 'SMTP-relay' traffic has to be allowed in System / Administration / Device Access which hasn't been automatically enabled on the WAN interface for me after upgrading and switching to MTA mode.

  • Hi All,

    the concept should be:

    • Device Access: used to define on which zone (in the future IP ) the service should listen on
    • Firewall Rule: to control XG Services like MTA, SSH, Web Admins, etc...

    This is not the way it should work.

    ,  this is the way on how it should work. Logic should be used.

    Can you confirm that?

    Thanks

Reply Children
No Data