Hey, JTV, welcome to the Astaro BB!
I don't know SonicWall, so may I ask a few questions? Can we assume that you want to make an internal mailserver available to both internal and external accountholders? Can we assume that you don't have a Mail Security subscription?
Cheers - Bob
We do have a Mail Security subscription, BUT right now we aren't going to be implementing it on these new subnets - the plan is to duplicate the existing setup, then work on implementing Astaro features later.
Traffic Source: Any
Traffic Service: SMTP
Traffic Destination: External (Address)
NAT mode: DNAT (Destination)
Destination: {Host definition of mail server IP}
Destination Service: {leave blank}
Automatic packet filter rule: {checked}
Traffic Source: {Host definition of mail server IP}
Traffic Service: SMTP
Traffic Destination: Internet
NAT mode: SNAT (Source)
Source: External (Address)
Source Service: {leave blank}
Automatic packet filter rule: {checked}
This is so easy that you might want to just skip the temporary solution. I just responded to that in another thread: SMTP Gateway
If you really do want to reproduce the settings on the SonicWall, you'll want two NAT rules:Traffic Source: Any
Traffic Service: SMTP
Traffic Destination: External (Address)
NAT mode: DNAT (Destination)
Destination: {Host definition of mail server IP}
Destination Service: {leave blank}
Automatic packet filter rule: {checked}
andTraffic Source: {Host definition of mail server IP}
Traffic Service: SMTP
Traffic Destination: Internet
NAT mode: SNAT (Source)
Source: External (Address)
Source Service: {leave blank}
Automatic packet filter rule: {checked}
You also will need packet filter rules to allow traffic between segments on different interfaces. If you have a public FQDN that identifies your mailserver, you may want to create an internal, static record that points at the internal IP.
All of the above assumes that you have a single WAN connection or that your public MX-record points to the primary External interface with the default gateway.
Cheers - Bob
Now, the Sonicwall has an additional entry:
Source: Mail Server Private IP
Translated: Mail Server Public IP
Inbound Interface: Any
Outbound Interface: WAN primary IP