This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Problems sending email notifications from Sophos XG

Hi all.

 

Quick question, if you know the answer, skip everything below this line: Can I completely disable EVERYTHING regarding email scanning on the Sophos XG series?

 

We are using a Sophos XG 105 Rev 2, it shipped with SFOS 16.05.5-233 (according to the box). After numerous unsuccessful attempts at sending a test email I decided to go ahead and download the latest ISO and install it. To my surprise it was "HW-SFOS_16.05.5_MR-5-233". Anyway after a complete reinstall of the Sophos XG software the problem continues.

From reading online I see Sophos XGs are still having issues sending email via o365, so I gave up on trying to use smtp.office365.com as an external mailserver.
We have a client that is using a Sophos XG 210 running firmware version "SFOS 16.01.1", using the 'Built-in Email server' works fine for notification purposes. So I decided to configure this Sophos XG 105 the exact same way (using the same from/to email addresses) but to my amazement even this doesn't work --- with the 'Built-in email server' selected on our Sophos the emails get stuck in the SMTP queue on the device regardless of the MTA / Legacy mode settings. No matter what settings I put into the email scanning section of the sophos it continues to hold and queue notification emails I attempt to send, as if though it is trying to scan them. Another factor that may be contributing to this is I have not registered the device yet since I belive the actual installation date is a little over 30 days out and I don't want to waste a month+ off their license, so technically many of those additional services are configurable/running to some extent, but not fully functioning.

What is really weird is when I look at the email log, the queued emails are coming from a random port on loopback address for the source (that makes sense well enough) but the DESTINATION address is ":: :24"

I've kept a window open just running tail -f /var/tslog/awarrenmta.log just to see what was happening every time i click the 'test email' button and to my amazement i see these sorts of lines:

 

Mail Transaction Started from 172.0.0.1:41366 to 216.32.181.42:24



This thread was automatically locked due to age.