Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

I don't receive emails when smtp smtps scan is activated

Hello everyone

 

I have a problem with my Sophos XG210.

I have a Exchange 2010 Server, before we had a self-signed certificate. We activated the email protection (because of spam), it worked perfectly.

Yesterday we have changed the certificate to an official one. This morning I can't receive any e-mail.

After some tests, I have disabled the SMTP and STMPS scanning on my business rule, and I receive my e-mail.

Now it works, but I receive spam again.

 

If you have any ideas ?

 

Thank you



This thread was automatically locked due to age.
Parents Reply Children
  • Some Non Delivery Reports (NDRs) were sent back, along the lines of Sophos Firewall couldn't deliver the message to the internal mail server due to an Internal Server Error.

    I only received this information second-hand, as no-one had forwarded on the NDR to my alternate e-mail address.

  • I sent an email to my client on an unrelated issue this morning - it hasn't been delivered and no NDR.

     

    no NDR to any test messages sent before swapping over to MTA mode either.

  • I was unable to trigger an NDR in my testing as well, but my clients had some of their customers who said they had received NDRs.

    I'll post the exact message once I can get my hands on one of them.

  • This is what i got back when i tried to send mail to the affected customer.

     

    Sophos Firewall was unable to send the following mail:

    ----------------------

    From: sender@company.com

    MessageID: <6ab0bfd80b5f4d60a099398793394648@server.com>

    Sent on: 2017-06-29 11:42:37

     

    Mail delivery to following recipients failed:

     

    recipient@othercompany.com- Internal Server Error

     

    ----------------------

  • Thanks for posting that.

    I got one of my client's client to send me an MMS of the error and it's identical to what you have seen.

    Hopefully Sophos can get to the root cause of this - 12 hours wasted on it and this is without looking at the ongoing brokenness of Windows security updates...

  • NP.

     

    got this response from the support about 30 minutes ago:

    The issue is identified with reach-ability of RBL servers. I would request you not to use RBL reject rule for scanning in the device. We have identified this issue as a BUG with id NC-19829.

    I will keep you informed with further information regarding this.

  • Thanks for the update. Would be nice if they put that info up somewhere so it's more widely circulated.

    There's not much in the way of anti-spam measures on the XG without using RBLs.

    Honestly, for the amount of money we're expected to hand over for a "next gen firewall" we really shouldn't be having to turn off the bulk of what makes it a "next gen firewall" to make the thing reliable.

    At this point I could probably achieve the same functionality with a pfSense box with lower costs, better reliability and better IPv6 support.

    Not been a happy Sophos customer nor partner for the last few months, on this issue and others.