This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Problems sending email notifications from Sophos XG

Hi all.

 

Quick question, if you know the answer, skip everything below this line: Can I completely disable EVERYTHING regarding email scanning on the Sophos XG series?

 

We are using a Sophos XG 105 Rev 2, it shipped with SFOS 16.05.5-233 (according to the box). After numerous unsuccessful attempts at sending a test email I decided to go ahead and download the latest ISO and install it. To my surprise it was "HW-SFOS_16.05.5_MR-5-233". Anyway after a complete reinstall of the Sophos XG software the problem continues.

From reading online I see Sophos XGs are still having issues sending email via o365, so I gave up on trying to use smtp.office365.com as an external mailserver.
We have a client that is using a Sophos XG 210 running firmware version "SFOS 16.01.1", using the 'Built-in Email server' works fine for notification purposes. So I decided to configure this Sophos XG 105 the exact same way (using the same from/to email addresses) but to my amazement even this doesn't work --- with the 'Built-in email server' selected on our Sophos the emails get stuck in the SMTP queue on the device regardless of the MTA / Legacy mode settings. No matter what settings I put into the email scanning section of the sophos it continues to hold and queue notification emails I attempt to send, as if though it is trying to scan them. Another factor that may be contributing to this is I have not registered the device yet since I belive the actual installation date is a little over 30 days out and I don't want to waste a month+ off their license, so technically many of those additional services are configurable/running to some extent, but not fully functioning.

What is really weird is when I look at the email log, the queued emails are coming from a random port on loopback address for the source (that makes sense well enough) but the DESTINATION address is ":: :24"

I've kept a window open just running tail -f /var/tslog/awarrenmta.log just to see what was happening every time i click the 'test email' button and to my amazement i see these sorts of lines:

 

Mail Transaction Started from 172.0.0.1:41366 to 216.32.181.42:24



This thread was automatically locked due to age.
Parents
  • i've got XG115 (SFOS 16.05.8 MR-8)

    We are trying to use the internal mail server to send backups by email.
    same problem, it get stuck in the Mail spool status - Failed.
    And when i check the logs it says "Email has been accepted by Device and queued for scanning" after that its just stuck.

    I've also looked for the ability to turn of email scanning just temporary for testing if there is something wrong.

    i believe that it have to do with the licensing for email protection, that maybe it wont scan, and therefore wont go through.

Reply
  • i've got XG115 (SFOS 16.05.8 MR-8)

    We are trying to use the internal mail server to send backups by email.
    same problem, it get stuck in the Mail spool status - Failed.
    And when i check the logs it says "Email has been accepted by Device and queued for scanning" after that its just stuck.

    I've also looked for the ability to turn of email scanning just temporary for testing if there is something wrong.

    i believe that it have to do with the licensing for email protection, that maybe it wont scan, and therefore wont go through.

Children