This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

MTA - Whitelist and Blacklist

Hello, after setting up MTA Email Protection, I noticed there is no Whitelist or Blacklist.  Not only for admin on the XG, but I don't see anywhere in the User Portal for users to manage a White/Black list.  Will this feature be added soon?

Thanks



This thread was automatically locked due to age.
Parents Reply
  • Ha-ha! So, if anybody interested, i've opened a ticket and got the answer:

    "I have gathered information and came to know that currently there is no option to add a list of whitelist/blacklist domain in the SMTP policy which is created for the MTA in v16.
    There is a running JIRA ticket for this at Sophos its called NC-15230 (and NC-13004)."

    What a bunch o crap, if you'll ask me!

     

Children
  • Hi Americo,

    It is a pending feature to whitelist/blacklist the sender domains in MTA mode on XG. Please cast your votes to this feature request here.

    This feature is only possible if the XG is configured in legacy mode for Email Protection. Refer the article here: community.sophos.com/.../

     To  allow/reject Emails to a particular domain you can configure an SMTP policy in Email> Policies> Add SMTP Policy> Domain> Accept/Reject.

    Thanks

    Sachin Gurung
    Team Lead | Sophos Technical Support
    Knowledge Base  |  @SophosSupport  |  Video tutorials
    Remember to like a post.  If a post (on a question thread) solves your question use the 'This helped me' link.

  • Any new info to get blacklist/whitelist option to MTA? In legacy mode work great but we can't switch to MTA because this function missing(There is no option when you create smtp policy to select sender)...

     

  • I would like to know the same thing, this was mentioned months ago as on the feature list. No word on the current status.

  • I know for our company that until this is not fixed in MTA mode(That we can whitelist/block senders in SMTP rule) we will not use MTA and without MTA we can't test Sandstorm and also can't buy Sandstorm license...

    P.S. We don't need per user rule! We need general rule which can't be override by user!

  • Hi

     

    I have White Listed Domains With MTA in XG 130.

     

    Here is how i did it:

    1) Configure MTA mode

    2) Goto Email -> Address Groups -> Add and create one for example in Name: WhiteListedDomains and in put the domain that you want to whitelist like this for example google.com

    3) Goto Email -> Policies and you have for sure one SMTP Policy in that policie click on edit and under Domains And Routing Target on Protected Domain add the Address Group Created Before (WhiteListedDomains) and save.

     

    And that's all

     

    I hope i could help.

  • But you don't have blacklist option...

  • I've tried configuring an SMTP policy as you've mentioned here and that doesn't work. 

  • Regards, Jelle

    Sophos XG210-HA (SFOS 18.0.4) on SG210 appliances with Sandstorm and 1x AP55
    Sophos Central with Intercept X Advanced, Device Encryption, Phish Threat, Mobile Control Advanced

    If a post solves your question use the 'This helped me' link.

  • Ha! They call it a solution! Now tell me how to block a TLD? you know, these pesky .work or .party or just simple .ru spam emails? The "Blocked email addresses" list will not accept "*@*.work" :-( They should've made the first list not "Allowed IP addresses/FQDNs" but "Blocked.." instead. And extended the mask to include just TLDs.

  • To be honest, in my opinion blacklisting a complete TLD seems not be a good solution. So I wouldn't implement that too. You never know who's going to send an email from such a TLD next time. Besides that I only see a few spam mails coming through. For these I'd like to see the greylisting feature work correctly. I bet that even the last spam mails are dropped then. The mentioned solution is more important to me regarding the whitelisting, as for example some important senders get blacklisted and don't do anything about it.

    Regards, Jelle

    Sophos XG210-HA (SFOS 18.0.4) on SG210 appliances with Sandstorm and 1x AP55
    Sophos Central with Intercept X Advanced, Device Encryption, Phish Threat, Mobile Control Advanced

    If a post solves your question use the 'This helped me' link.