This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Port Forwarding to another UTM connected via RED

Hi,

 

I'm using the UTM for many years now, but now I have a problem I got stuck..

 

The Environment:

Site A (a rented Server):

Small Server, virtual UTM (UTM A), many public IPs, fast Internetconnection

 

Site B:

big hardware UTM (UTM B), dyn. IP, not so fast Internetconnection (100/40), all other Servers are located here

 

I have a good working UTM to UTM Red Tunnel between Site A&B and until now I'm using this szenario:

- MX Records points to site A

- the Emailprotection of UTM A processes the Mail

- the Email gets forwarded over the Red Tunnel directly to the Mailserver at Site B

 

This worked for years now, but i wan't to make the "remote" UTM A dumber, so everything important is at site B

 

So what i want:

- MX Records points to site A

- the SMTP Port is forwarded to UTM B

- UTM B makes the Processing of the Email and delivers it to the Exchange

 

I tried it this was:

- on UTM A I created a DNAT:

    Source: Any

    Service: SMTP

    Destination: the Interface with the Public IP the MX record points to

    Change Destination: the Red Tunnel IP of UTM B

    Change Service: SMTP

    automatic Firewall Rules

- on UTM A I created a masquerading for the Red Tunnel network

- on UTM B i allowed the RED IP of UTM A as Upstream Host in the Email Protection (but the allow only is not selected)

 

I tried to test this construct via telnet on Port 25 but I can't connect to any SMTP Server (Timeout).

I checked the Firewall Logs on both UTMs but there are no entrys for this problem.

 

Has anyone an idea where the mistake could be...

 

Greets Daniel



This thread was automatically locked due to age.
Parents
  • Hallo Daniel,

    I'm a visual-tactile learner, so I would have to make a diagram to follow your explanation.  I suspect that you just need a Full NAT instead of a DNAT.  This is a problem similar to Accessing Internal or DMZ Webserver from Internal Network.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Hi Bob,

     

    the FullNAT worked immediately! Thanks a lot!

    Has anyone Security Concerns about this construct? Would it be better to route this "forwarded external traffic" through an separate Red Tunnel?

     

    Greets Daniel

  • Hi,

     

    I have found another solution for this problem!

    As I said before I have a complete /29 Subnet available at Site A. From the Internet the hole Traffic for this Subnet is routed over another public IP (not within this subnet) so I could simply use it by adding the IPs as "Additional IPs" to this Interface. But the fact that I have a complete Subnet available brought me to another Idea:

    Why not to us this Subnet for the Red Tunnel?

     

    Tried it and it worked perfekt. So now i have 5 IP Addresses directly assigned to a Interface on UTM B! The only downside is, that I'm loosing one IP for the Red Interface on UTM A.

     

    Greets

    Daniel

Reply
  • Hi,

     

    I have found another solution for this problem!

    As I said before I have a complete /29 Subnet available at Site A. From the Internet the hole Traffic for this Subnet is routed over another public IP (not within this subnet) so I could simply use it by adding the IPs as "Additional IPs" to this Interface. But the fact that I have a complete Subnet available brought me to another Idea:

    Why not to us this Subnet for the Red Tunnel?

     

    Tried it and it worked perfekt. So now i have 5 IP Addresses directly assigned to a Interface on UTM B! The only downside is, that I'm loosing one IP for the Red Interface on UTM A.

     

    Greets

    Daniel

Children
No Data