Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DNAT Rule for SMTP Traffic

Evening All,

Slight bit of a noob with the Sophos UTM so please bare with me, as i could be doing something completely backwards.

So I have a Sophos SG550 UTM 9 Device, and i'm wanting to pass traffic through from Symantec messagelabs to my Internal Exchange servers, We do not have the Email Protection Licence as the company is to strapped for cash for this. 

Currently have the below interfaces

External Interface within a DMZ area - this is also used to allow Internet traffic out on one IP, have an additional IP for the Exchange traffic to be passed too

Internal Interface - for all internal traffic to access

 

I currently have a DNAT rule which passes traffic from my external adaptor through to the Exchange servers

Source - Messagelabs IPs

Service - Email Messaging 

Destination - External Exchange 

convert to - Internal Exchange Server

Firewall - Auto Create

 

Now i can see traffic going through the firewall but symantec moans that it doesn't have a route through i'm assuming this is a problem that it can't get back to symantec, tried adding firewall rules to allow the traffic and setting nat rules but to no help.

 

So thought i'd throw my questions here to see if anyone could help point me in a decent direction. I'm no network engineer.



This thread was automatically locked due to age.
  • Hi Phil,

     

    your NAT rule is correct. You have to translate the traffic to your internal Mail-Server. 

    I think the problem lays within your E-Mail Server configuration. Are you using Exchange or something else? (I can only help with Exchange :) )

     

    Maybe activate logging for the NAT rule too, so that we can analyse the traffic passing through it.

     

    Regards,

     

    Ole

  • Hi, Phil, and welcome to the UTM Community!

    What do you learn from doing #1 in Rulz?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA