Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Upgrade: UTM120 -> SG125 gone bad

I got a new SG125 (V9) appliance and attempted to replace my old UTM120 (V8) with it.
I uploaded the last settings backup into the SG125 and when I checked all the settings seemed to have come over correctly and everything appeared fine.

When I did the physical replacement and put the new appliance on the network everything seemed to work. Our site to site VPN was up, internet surfing and file uploading worked, etc... I thought everything was golden.
Then I found there was no inbound email traffic. Nothing was coming in over the LAN and anyone attempting to send or receive emails from outside the LAN was getting connection errors. I attempted to telnet to the appliance over port 25 from the WAN side and couldn't connect. Then I tried the LAN side and was able to connect and sent an email manually with no problems. 

One final thing I attempted was setting up a firewall rule to pass all traffic. While that ran, I tried connecting from the WAN side again and checked the log but there were no connection attempts showing.

* I am using the SMTP Proxy in simple mode (no profiles) which then either relays (when applicable) emails or delivers to the internal email server.
* NAT and Firewall settings are all the same between the appliances. Nothing is blocking or changing inbound email ports.

...and yet somewhere, somehow all the email ports are being blocked...

In the end I had to put the old 120 back in place. [:(]

Does anyone have any ideas what I might be missing or should check?

Thanks
-- 
Loren McDonald


This thread was automatically locked due to age.
  • You neglected to include the precise UTM Version you were running on the new appliance.  There is a known issue with SSL/TLS SMTP email traffic flow on 9.210 and earlier version of 9.3xx.  If you are not using the Wireless Security feature on the UTM, with the AP in Separate Zone mode (there are several issues with this), update to 9.304 -- this patches the SMTP email flow issues that are known.

    If the above is not applicable, you probably should start a support case with Sophos.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

  • One other issue... in newer versions of 9.3xx there is an issue with having routed domains listed for SMTP Profiles, but nothing in the Default routed domain list.  You can add a "dummy" entry in the Default profile list and that would solve that issue.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

  • The version is 9.205-13 so it's prior to the bugs that arose in 9.210. And since I can't connect through a raw telnet session (no SSL/TSL) I again doubt that bug is what is plaguing me but updating is a good idea. I can try and see if that fixes anything.

    Since I'm using simple mode the routed domains doesn't come into play here.
  • I updated to the most recent version and its still a nogo.
  • Those were the main things that came to mind; you have deeper issues.  I recommend you start a support case with Sophos; posting here does not start an official support case.  If you have Standard support, you need to contact your reseller to start a support case, if you have Premium Support, then you can opt to create a case directly at https://myutm.sophos.com .

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

  • After some more digging I finally found the issue... It was the ARP table on the cable modem. Once the provider cleared that email started working like a champ.
  • Thanks for letting us know.

    That's on my standard list of instructions for every installation.  Hard to believe that your reseller didn't mention that in advance.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?