Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos UTM - Packets dropped, without Reason

Hello,

the situation is, i have a mail gateway and forward mails trough the sophos utm to my internal mailserver.

I've enabled DNAT to the internal Server. The Mailgateway (MailCleaner) communicates from the Internet with the internal Mailserver without Problems (Allowed port 25 to Internal Mailserver).

But when i open the Firewall Tab, there are always blocked SMTP packets.

The Firewall log shows the following output when i try the Adress Verification via SMTP:

10:31:06 Packet filter rule #6 TCP  
62.11x.xx.115 : 48445
192.168.xx.xx : 25
 
[SYN] len=60 ttl=48 tos=0x00 srcmac=00:01:5c:xx:xx:xx dstmac=00:0c:xx:xx:xx:xx
10:31:06   TCP  
62.11x.xx.115 : 48445
62.xx.xx.xx : 25
 
[RST] len=40 ttl=49 tos=0x00 srcmac=00:01:5c:xx:xx:xx dstmac=00:0c:xx:xx:xx:xx
10:31:06   TCP  
62.11x.xx.115 : 48445
62.xx.xx.xx : 25
 
[RST] len=40 ttl=49 tos=0x00 srcmac=00:01:5c:xx:xx:xx dstmac=00:0c:xx:xx:xx:x

I also have tried to fix it with a new firewall rule: 62.11x.xxx.115:1-65535 -> SMTP -> 62.xx.xx.xx but i receive the same error scheme.

 

Could somebody explain or help me to fix that, my Mailgateway is always on first position in my Firewalls blocked paket list!



This thread was automatically locked due to age.
Parents
  • Those packets are RST Packets. Means RESET. https://stackoverflow.com/questions/7735618/tcp-rst-packet-details

    Basically UTM only logs, that this packet is dropped. 

    (Most likely you have following Option enabled: Network Protection > Firewall > Advanced : 

    Block invalid packets: If enabled, the firewall will check the data packets for conntrack entries. The conntrack entries will be generated by sending connection initializing packets, for example, TCP SYN or ICMP echo requests. If someone tries to send a packet which does not match to an existing connection, for example, TCP ACK or ICMP echo reply and Sophos UTM cannot find a matching TCP SYN or ICMP echo request via the conntrack entry the data packet is invalid and will be dropped. A record will be written to the firewall log.)

     

    There is an issue in the communication.

    You need to dump the connection. Those RST Pakets are basically useless for the communication and will be dropped. 

    __________________________________________________________________________________________________________________

  • Thank you for the exact explanation of what the real problem is.

    Unfortunately, I can not change the communication between MailCleaner and the internal mail server.

    I did not enable the "Block invalid packets" option. Is there a way to build an exception rule for this host so that no RST error is written to the log?

Reply
  • Thank you for the exact explanation of what the real problem is.

    Unfortunately, I can not change the communication between MailCleaner and the internal mail server.

    I did not enable the "Block invalid packets" option. Is there a way to build an exception rule for this host so that no RST error is written to the log?

Children
No Data