Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Mail Being blocked as SPAM

Hi,

We run a UTM9 (virtual appliance) and have many customers using hardware SG appliances.  This afternoon we have have many reports of email issues, with sending and receiving from a variety of company addresses and gmail.com / hotmail.com domains.

According to the mail manager all of the emails are being dropped as confirmed spam.  Is this a dodgy pattern update?

Internally we are currently on FW 9.601-5 and pattern 161467.

I have switched reject at smtp time to off and emails are now getting quarantined.  Have logged a support call with Sophos via email and am in the phone support queue.

Any one else experiencing this?

Rgds

Asim



This thread was automatically locked due to age.
Parents Reply Children
  • I just went through the steps on our own UTM.  Seems to have worked as emails are no longer appended with *SPAM*.

     

    About to test on another client.

  • Thanks. Finally reset and appears fixed.

    I missed the first link and was having trouble accessing the root as was trying to access it directly from Putty.

    https://community.sophos.com/kb/en-us/133645 is important if you are unfamiliar with SSH access

    Typically, I got through to support again just after I had completed the exercise and wasn't totally sure it was sorted.

  • Sorted!!

    We ran the amended commands as per the Sophos Advisory and legitimate e-mails are no longer being wrongfully categorised as SPAM.

    As we run a pair of UTM Appliances in an Active-Passive configuration, I was advised by Sophos Support to also run the commands on the standby appliance. I did this using the HA_UTILS SSH command via a Putty session.

    We are in a fortunate position whereby our inbound e-mails are scanned by a pair of Cisco Ironport Mail Appliances before being forwarded to the UTM Appliances for further processing. This multi-vendor approach indeed saved us a lot of grief. Most inbound SPAM is detected and blocked by the Ironports and the UTM picks off the remaining few that make it through. Without this extra layer of defence, our situation would have been a whole lot worse.

    Regards,

    John P

    2 x SG450 (Version 9.714-4)

    HA = Active-Passive