Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

smtp.office365.com - fw rule

Hello, 

I have two XGS2300 in A/P HA (SFOS 19.0.0 GA-Build317)

I have problem with firewall rule that allow TCP: 587 to fqdn smtp.office.365.com from internal LAN

from time to time traffic did not match this rule because firewall has problem to use/resolve all IP address that is hosted by fqdn smtp.office365.com

Look at attach:

   -  in "smtp.office365.com-DNSresolveBySophosFW.jpg" you can see most of IP addesses resolved from fqdn smtp.office36 5.com

   - in "smtp.office365.com-blockedByFirewall.jpg" you can see that traffic from 10.0.84.20 > 40.99.150.82 TCP 587 is not matched by fw rule for smtp.office365.com

for this moment i had to add "Any" as destination instead of "smtp.office365.com" any idea?



This thread was automatically locked due to age.
Parents Reply Children
  • why? this is last fw rule for logging remain non-allowed traffic.

    "DenyAll" is simple Drop "Any" "Any" rule.

    you can see full seqvence

             - #136 TCP:587 destination "smtp.office365.com"

             - # 62  TCP:587 destination "any" - temporary rule becouse rule #136 is not working correctly

             - # 1 "DennyALL" logging remain non-allowed traffic

  • Hi,

    on my XG, 587 was not part of the smtps service definition, I had to add it.

    ian

    XG115W - v20.0.1 MR-1 - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • my XGS already have this definition.

  • I've seen this behaviour a couple of times, I tried finding the cause with the help of Sophos Support but it proved fruitless. It didn't happen often enough to justify spending the time debugged the logs - we just switched to use the IP ranges on the firewall rule and moved on with life. Probably not the silver bullet you were hoping for,..

    Regards