Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos UTM - Packets dropped, without Reason

Hello,

the situation is, i have a mail gateway and forward mails trough the sophos utm to my internal mailserver.

I've enabled DNAT to the internal Server. The Mailgateway (MailCleaner) communicates from the Internet with the internal Mailserver without Problems (Allowed port 25 to Internal Mailserver).

But when i open the Firewall Tab, there are always blocked SMTP packets.

The Firewall log shows the following output when i try the Adress Verification via SMTP:

10:31:06 Packet filter rule #6 TCP  
62.11x.xx.115 : 48445
192.168.xx.xx : 25
 
[SYN] len=60 ttl=48 tos=0x00 srcmac=00:01:5c:xx:xx:xx dstmac=00:0c:xx:xx:xx:xx
10:31:06   TCP  
62.11x.xx.115 : 48445
62.xx.xx.xx : 25
 
[RST] len=40 ttl=49 tos=0x00 srcmac=00:01:5c:xx:xx:xx dstmac=00:0c:xx:xx:xx:xx
10:31:06   TCP  
62.11x.xx.115 : 48445
62.xx.xx.xx : 25
 
[RST] len=40 ttl=49 tos=0x00 srcmac=00:01:5c:xx:xx:xx dstmac=00:0c:xx:xx:xx:x

I also have tried to fix it with a new firewall rule: 62.11x.xxx.115:1-65535 -> SMTP -> 62.xx.xx.xx but i receive the same error scheme.

 

Could somebody explain or help me to fix that, my Mailgateway is always on first position in my Firewalls blocked paket list!



This thread was automatically locked due to age.
Parents
  • Hi  

    These RST packets are being dropped because the connection tracker is no longer tracking the connection. It has no idea where to send the packet and, were the server to receive the packet, it likely would have no idea what to do with the packet. I would also suggest you to check the sequence number of the packets in order to see if there are any re-transmitted packets.

    You may also refer this KBA Sophos UTM: Firewall log shows dropped packets with tcpflags="ACK RST" or "ACK FIN" Hope this helps.

    Regards

    Jaydeep

  • The problem is the Recipient Verification, if the E-Mail address is non existant then the error with the RST packets happen.

     

    *I changed the verification to a local method, the problem should be solved now. Thank you.

  • Basically is this an issue or not? 

    I mean, RST Pakets are most likely useless. 

    Simply filter the log on the CLI to those criteria and check, if those RST Pakets occur the whole time. 

    __________________________________________________________________________________________________________________

  • No it's not an issue. I just wanted to know if i can disable the logging for those RST Pakets for my Mailgateway.

    The RST Pakets only occur if someone tries to send to a non existing E-Mail address (Mailgateway asks internal Mailserver for the Adress, if it's not existent you will receive a message containing: 550 Callout verification failed: 550 5.1.1 <asd@xxx.xx>: Recipient address rejected: User unknown in virtual mailbox table)

    I don't know why the Session is not closed with a FIN Paket. - And i don't want to debug the network traffic, the server logs are okay.

    Anyway it's not a big deal, it's only my personal domain with some Mailboxes, it's possible for me to manage them seperatly on the MGW and Mailserver.

     

    Without smtp callout the Firewall Top Dropped Destination Services/Hosts won't look like this anymore:

     

     

    Thank you for your help!

Reply
  • No it's not an issue. I just wanted to know if i can disable the logging for those RST Pakets for my Mailgateway.

    The RST Pakets only occur if someone tries to send to a non existing E-Mail address (Mailgateway asks internal Mailserver for the Adress, if it's not existent you will receive a message containing: 550 Callout verification failed: 550 5.1.1 <asd@xxx.xx>: Recipient address rejected: User unknown in virtual mailbox table)

    I don't know why the Session is not closed with a FIN Paket. - And i don't want to debug the network traffic, the server logs are okay.

    Anyway it's not a big deal, it's only my personal domain with some Mailboxes, it's possible for me to manage them seperatly on the MGW and Mailserver.

     

    Without smtp callout the Firewall Top Dropped Destination Services/Hosts won't look like this anymore:

     

     

    Thank you for your help!

Children
No Data