Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

I don't receive emails when smtp smtps scan is activated

Hello everyone

 

I have a problem with my Sophos XG210.

I have a Exchange 2010 Server, before we had a self-signed certificate. We activated the email protection (because of spam), it worked perfectly.

Yesterday we have changed the certificate to an official one. This morning I can't receive any e-mail.

After some tests, I have disabled the SMTP and STMPS scanning on my business rule, and I receive my e-mail.

Now it works, but I receive spam again.

 

If you have any ideas ?

 

Thank you



This thread was automatically locked due to age.
Parents
  • The bug seems to be on the list

    Dnsbl-1.uceprotect.net

    Affects both Sophos and Cyberoam / Sophos

    It is a very serious problem since some emails enter ok, others are rejected and others are discarded.

  • The bug seems to be fixed:

    https://community.sophos.com/kb/en-us/127052

    Anyone can confirm that?

    Thanks

  • The bug is still there if you have an unresponsive RBL in either of the Premium or Standard RBL lists.

    The instructions for removing the RBL list is simply removing the unresponsive RBL system from being queried, resulting in a timed out SMTP session.

    For example if you add bad.psky.me to either list - which appears to be down and has been down since I first noticed this problem - and have the XG Firewall in Legacy Mode, you'll end up with most of your SMTP sessions to an internal mail server timing out.

    tl;dr an unresponsive RBL will effectively DoS a Legacy Mode configuration.

    Switching to MTA Mode makes an unresponsive RBL simply delay transmission to an internal mail server.

    The instructions in that article would be much more useful if it gave guidance on removing RBLs one at a time to see which RBL service is unresponsive.

Reply
  • The bug is still there if you have an unresponsive RBL in either of the Premium or Standard RBL lists.

    The instructions for removing the RBL list is simply removing the unresponsive RBL system from being queried, resulting in a timed out SMTP session.

    For example if you add bad.psky.me to either list - which appears to be down and has been down since I first noticed this problem - and have the XG Firewall in Legacy Mode, you'll end up with most of your SMTP sessions to an internal mail server timing out.

    tl;dr an unresponsive RBL will effectively DoS a Legacy Mode configuration.

    Switching to MTA Mode makes an unresponsive RBL simply delay transmission to an internal mail server.

    The instructions in that article would be much more useful if it gave guidance on removing RBLs one at a time to see which RBL service is unresponsive.

Children