Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Should this DNAT rule work?

This was set up by our VAR, and it doesn't seem to work.

Position 1:

DNAT (Destination)

For traffic from: (Any)

Using service: Group (8008, 993, 8843, 995, 587, 465, 5223)

Going to: WAN (Address)

Change the destination to: (Internal mail server)

Automatic firewall rule: true

The Sophos user portal is accessible externally, and the same port forwards on our old firewall (Lotus Foundations) work without issue.


A visit to "canyouseeme.org" says the same (port 3333 open), but every other service listed in the group times out.

I read a web post from 2014 stating that specifying a group of services in the "Using service" box doesn't work.  Is this still the case?

Tks

SG135w - 9.403.4



This thread was automatically locked due to age.
Parents Reply
  • I guess Rule 3.1 would have best described the situation.  The SSL VPN would connect, but no devices were reachable.

    You could also connect via PPTP, and everything would work.  That's what fooled me (PPTP was assigning the correct default

    gateway via DHCP).

    Thanks to all...

Children
No Data