Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Black Hole NAT not working

Every day we have random people trying to authenticate into our hardware spam filter in order to spoof emails and whatnot. What I set up on the UTM9 was a black hole NAT. So under Network Protection > NAT > NAT I have a DNAT set up. In the "For traffic from:" I have a group called Spammers/Hackers which has a list of IPs of the offenders. "Using service" is set to Any and "Going to" is set to "External Address Group" which is a list of all our networks both using WAN and LAN IPs. It is then set to "Change the destination to" an IP of 240.0.0.0. Our IP scheme is using a class B for reference. Also checked is the automatic firewall rule option.

However it doesn't appear to be working...I say this because I went to add an IP to the offender list and it said it already existed as I had added it last week, but the offender was still able to attempt to authenticate to our security gateway. Did I set this up wrong? Any help would be appreciated.



This thread was automatically locked due to age.
Parents Reply Children
  • SMTP should be included in the "Any" service, Olsi, so I wonder what we're not seeing...

    Chad, are you saying that the hacker's IP doesn't show up in the firewall log - that his packets don't qualify?  Show us the Edit of the Hackers group showing the Host definition for this IP.  Also, show us the Edit of that Host.

    Confirm that the 'Going to:' is "External (Internet) (Address)" or "External (Internet) (Network)."

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • I think DNAT works better with service defined Bob. If not, than should be replaced with SNAT rule. I liker to test by myself, but is not possible today

  • something is missing from host configuration. 

  • I've had this for a long time:

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?