This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion
Sven OlafSchuranover 1 year ago
Hello,
I need to change target port to internl exchange server to port 5252. MTA mode uses port 25 as normal.
Cause of reicipent filter with callout needed, this is not working on smtp port 25, cause of exchange implementation.
This have to setup on another port diffrent from port 25.
I have added a NAT rule and Firewall rule, but it is not used.
Sven
This thread was automatically locked due to age.
- Cancel
Top Replies
- Hi Sven, Thank you for reaching out to Sophos Community. Have you tried to use any how-to videos, documentation, Sophos Assistant, or KBA to try to check the issue? Can you share your configuration…
Erick Janover 1 year ago+1
0Erick Janover 1 year ago
Hi Sven,
Thank you for reaching out to Sophos Community.
Have you tried to use any how-to videos, documentation, Sophos Assistant, or KBA to try tocheck the issue?
Can you share your configuration and FW rules?
Then kindly try to turn off the smtp on the Device access, then check and test.
You may also refer to the following KB
support.sophos.com/.../KB-000038880
Erick Jan
Community Support Engineer | Sophos Technical Support
Sophos Support Videos|Product Documentation|@SophosSupport |Sign up for SMS Alerts
If a post solvesyourquestion use the'Verify Answer'link.- Cancel
- Vote Up+1Vote Down
- Cancel
0Sven OlafSchuranover 1 year agoin reply to Erick Jan
Hello,
How to Nat is known well.
I like to Nat the smtp MTA proxy sending port 25, when send mails to exchange, from target port 25 to port 5252.
I have setup a NAT rule, Firewall IPs as source, destination Excachenge, dest port 25, to port 5252, and I have a firewall rule allowing this traffic.
But it is nor working.
Sven
- Cancel
- Vote Up0Vote Down
- Cancel
0Vivek Jagadover 1 year agoin reply to Sven OlafSchuran
Hello Sven OlafSchuran,
Sophos Firewall inspects allSMTP/Sraffic on the standard ports by default. Now you can use service-param to turn on inspection of traffic
sent over non-standard ports. Now if the port used 5252 is not working for the SMTP/S it would be great if you can try telnet or capture traffic on that port to understand the traffic flow -https://support.sophos.com/support/s/article/KB-000035768?language=en_USCreate and download a packet capture : https://support.sophos.com/support/s/article/KB-000037007?language=en_US
Thanks & Regards,
_______________________________________________________________Vivek Jagad| Team Lead, Global Support & Services
Log a Support Case|Sophos Service Guide
Best Practices – Support Case
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.- Cancel
- Vote Up+1Vote Down
- Cancel
0Sven OlafSchuranover 1 year agoin reply to Vivek Jagad
I have MTA mode running. When MTA mode sending Mails to internal Mailbox Excahnge it uses port 25. This is working as it should.
But to get reicipoient filter working I must send send Mail to the internal exchangfe server via port 5252. I have done this in SG UTM witrh a NAT rule, I am trying it the same way in XGS. But NAT is not working.
Sven
- Cancel
- Vote Up0Vote Down
- Cancel
0Vivek Jagadover 1 year agoin reply to Sven OlafSchuran
Hey Sven OlafSchuran try the steps mentioned in the following steps:https://doc.sophos.com/nsg/sophos-firewall/19.5/help/en-us/webhelp/onlinehelp/AdministratorHelp/RulesAndPolicies/NATRules/RulesPoliciesCreateDNATAndFirewallRulesForInternalServers/index.html
Thanks & Regards,
_______________________________________________________________Vivek Jagad| Team Lead, Global Support & Services
Log a Support Case|Sophos Service Guide
Best Practices – Support Case
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.- Cancel
- Vote Up+1Vote Down
- Cancel
0Sven OlafSchuranover 1 year agoin reply to Vivek Jagad
I do not want external to internal.
I want internal firewall IP destination port 25 sending to internal exchange changed to port 5252.
I have a NAT Rule but it is not working.
- Cancel
- Vote Up0Vote Down
- Cancel
0LuCar Toniover 1 year agoin reply to Sven OlafSchuran
Please show a screenshot of your NAT rule.
__________________________________________________________________________________________________________________
- Cancel
- Vote Up0Vote Down
- Cancel
0Sven OlafSchuranover 1 year agoin reply to LuCar Toni
- Cancel
- Vote Up0Vote Down
- Cancel
0Vivek Jagadover 1 year agoin reply to Sven OlafSchuran
Hey Sven OlafSchuran, mention the smtp_5252 in the original service and the under the translated service (PAT) SMTP_25
Thanks & Regards,
_______________________________________________________________Vivek Jagad| Team Lead, Global Support & Services
Log a Support Case|Sophos Service Guide
Best Practices – Support Case
Sophos Community | Product Documentation | Sophos Techvids | SMS
If a post solves your question please use the 'Verify Answer' button.- Cancel
- Vote Up+1Vote Down
- Cancel
0Sven OlafSchuranover 1 year agoin reply to Vivek Jagad
I smtp MTA on XGS shall send its mails to exchang server on port 5252. Standard port is 25. So I must change 25 original service to port 5252. Your Idea is changeing 5252 to 25.
- Cancel
- Vote Up0Vote Down
- Cancel