It seems a lot of people ask a similar question on this forum, but I can't seem to finds one that's having the same issue I am. I can't seem to block access to my mail server's HTTPS interface. I've tried doing a DNAT to "Nowhere" and a firewall drop rule. With the firewall rule I was able to stop mail flow, but not access to the server's web interface. I've tried simply turning off the explicit allow rule, tried adding an explicit drop above it, even tried a Sources: Any, Services: Any, Destinations: Exchange Server at the top of the rules (this is what blocked mail flow). I've tried adding a DNAT with From (Specific Test IP), Service: Any, Going to: External Interface -- still was able to get to the mail server just fine.
I'm trying to block a particular host from the mail server because it keeps locking on of our users out. I'm not sure if it's a brute force password guessing or what, but she's locked out again before I can unlock her and hit refresh to check on it in our lock out tool.
Here's a little about what I have setup and rules I can find applied to the Exchange Server:
There are 3 inbound firewall rules setup to allow access to it: Rules 1 & 2 allow SMTP connections from MS servers to our mail server (they do our spam filtering) and the 3rd rule allows HTTPS access to our mail server.
I have a DNAT rule setup for when we fail over to our backup internet connection, mail gets pushed to the mail server from MS's servers. There are no DNAT's for the normal connection -- the firewall just passes the IP through to the server.
The Exchange server is in the Intrusion Prevention -> Performance Tuning section listed as a web server, but I wouldn't think that would automatically allow it (and I did try to remove it and see what happened -- nothing).
I have setup an exception in our web filter to make sure our internet sites aren't blocked by URL or Content Filtered (which would include our email server) -- but I would really hope the web filter rules wouldn't be applied to a connection from outside our Local Networks range.
We're running Sophos SG430 UTM firmware 9.402-7
Any help would be greatly appreciated!
This thread was automatically locked due to age.