Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall blocking

Hello,

I have added a Network Definitions group called "Blocked Attackers" and added several IP addresses and IP subnets.
I added a firewall rule (on position 1) with the following settings:

Sources: Blocked Attackers
Services: Any
Destinations: Any
Action: Drop (also tried reject)

The rule is enabled but I still see the IP address appear on the SMTP proxy trying to authenticate.

Am I missing something here?



This thread was automatically locked due to age.
Parents Reply
  • Because I'm using AD users to relay mail, also for any cloud apps I might be using in the future.
    I could have choosen for Allowed Hosts/Network but in this case I have choosen for Allowed Users/Groups.

    I don't really know why I should enable or disable Transparent Mode, it's still not really clear for me what it does and what the impact is for the current configuration.

    I have to say I'm quite new to UTM so maybe that's the whole issue? :)

Children