Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

MTA - mail relay does not need authentication

Hello, 

I set up Sophox XG 210 (SFOS 16.05.2 MR-2) in MTA Mode. My goal is to use sophos xg as mail relay for external computers.

Added smtp policy (relay allowed for my own Exchange online domain). 

In settings for relay I added "any" to hosts permitted for relay, activated "authenticated relay" and added a local created user.

 

Unfortunately Sophos does not need the credentials of this user for relaying. I can send mails without any authentication (which results in an open relay obviously). When I enter credentials, I get the message "authentication failed".

 

Does anyone have an idea, what I did wrong?



This thread was automatically locked due to age.
Parents
  • René,

    Are you using AD users ? Did you try to use a local user and see if Email Relay works?

    Anything useful from the logs?

    Thanks

  • Hi Luk, 

    thank you for your reply!

    We use AD-Integration for SSL VPN Remote Access. 

    For eMail Relay I would like to use a local user. For testing I added both to the authenticated users - but still no luck with their credentials. Mail relay works still only without credentials.

    I do not see any helpful entry in the log viewer (took a look in every subsystem that is available in log viewer).

     

    What seems also weird to me: even if the field "allow relay from hosts/networks" is completely empty (even "any" is not selected) I am able to relay mail. 

    This seems not to be ok to me. 

     

    Any ideas on this?

Reply
  • Hi Luk, 

    thank you for your reply!

    We use AD-Integration for SSL VPN Remote Access. 

    For eMail Relay I would like to use a local user. For testing I added both to the authenticated users - but still no luck with their credentials. Mail relay works still only without credentials.

    I do not see any helpful entry in the log viewer (took a look in every subsystem that is available in log viewer).

     

    What seems also weird to me: even if the field "allow relay from hosts/networks" is completely empty (even "any" is not selected) I am able to relay mail. 

    This seems not to be ok to me. 

     

    Any ideas on this?

Children
No Data