This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SPX Portal Not Working

Trying to get SPX email encryption working. Sophos XG Home v 18.0.4-MR4

The email protection is set up as MTA mode.  Normal email routing and deliver is working fine.

I've created the SPX template and when I try to send an email with the SPX header set to yes, the firewall holds the emails in quarantine as it should since the user has not created a password yet,, and sends the SPX registration email, which is received by the end user The link in the email is correct. The link properly resolves to the firewall's WAN interface IP.

However, clicking on the link results in a 'This Site cannot be reached' page.  Reason:  Connection Refused.

When I do a packet capture on the firewall, I see the request coming in on the correct port, and the status for the packed is 'Consumed'. 

Nothing is logged on the firewall report indicating anything is dropping or rejecting the request.

I'm stumped here.  Tried rebooting the firewall, recreating the SPX template, re-configuring the encryption settings.  

Any help would be appreciated.



This thread was automatically locked due to age.
Parents
  • FormerMember
    0 FormerMember

    Hi Craig, Can you verify your SPX portal settings? Have you added the SPX template into the SMTP route & Scan policy for your domain under "Domains and routing target" section?
    Also, is there any hostname set into Encryption settings?

  • I have not.  It was my understanding that if I added the SPX template to the Domains and Targeting section,  all email would be encrypted not just email where the sender sets the SPX-X header to 'yes',  Am I misunderstanding how this works?  I do not want all email encrypted, just when the SPX header is set. 

Reply
  • I have not.  It was my understanding that if I added the SPX template to the Domains and Targeting section,  all email would be encrypted not just email where the sender sets the SPX-X header to 'yes',  Am I misunderstanding how this works?  I do not want all email encrypted, just when the SPX header is set. 

Children
No Data