This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall not blocking SMTP

Hello everyone,
Don't know if I should post this on Email protection but I'll start here as the issue is also firewall related.
I am receiving tons of spam daily (bulk email) and the RBLs are not doing a good job, so I created a rule to block a "spamsenders" group I created.
I am adding to this group the IP addresses that this spam is coming from but no connections are being rejected.  I can still see email coming through from these IPs that I blocked on the rule.
The rule is: spam_senders_group --> any_service --> all_my_externalIPs action: reject and it is on the top of the rules.
Is Email processing happening before the firewall rules??
I would doubt it as I have the country blocking enabled and I can see traffic coming to my SMTP port being blocked by the "country blocked" rule.
What am I missing?
I have a ASG220 version 9.204-20.
Thanks for any input!


This thread was automatically locked due to age.
Parents
  • All good stuff above.

    And, it's possible that these aren't actually spams.  How about an example of such an email with header where your domain and public IP are obfuscated.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • All good stuff above.

    And, it's possible that these aren't actually spams.  How about an example of such an email with header where your domain and public IP are obfuscated.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data