Help us enhance your Sophos Community experience. Share your thoughts in our Sophos Community survey.

Sophos Firewall blocking outgoing IPv6 SMTP traffic

Hello,

I'm trying to configure SMTP on Sophos Firewall (SFOS 20.0.0 GA-Build222) : everything is running smoothly in IPv4, but Firewall is blocking outgoing IPv6 SMTP traffic : 

I tried to define all kinds of (IPv6) rules to allow this traffic without success : with or without 'Scan SMTP' enabled, from any zone to any zone, with or without linked NAT:

Is it possible to have an internal SMTP server in IPv4 relaying email to Sophos Firewall in IPv4 and Sophos Firewall sending emails to Internet over IPv6?

Thanks,

Nicolas



Edited TAGs
[edited by: emmosophos at 5:39 PM (GMT -8) on 26 Jan 2024]
  • Hi,

    Just to be complete, if you follow this way, you won't be able to SNAT your SMTP trafic... You're in firewall rule id 0 and there isn't any (s)NAT applying to it.

    However, you can SNAT all your system-generated trafic with this console command : 

    set advanced-firewall sys-traffic-nat delete destination 0.0.0.0 netmask 0.0.0.0 interface wan snatip xxx.xxx.xxx.xxx

    For IPv6, as nothing is working by default, I just put my SMTP IPv6 address as main address on my wan interface.

    Anyway, everything is working as expected, as any IPv4/IPv6 SMTP relay!

    Cheers,

    Nicolas

  • Hi,

    I discovered today that I had to disable also incoming emails rules in firewall : recipient verification with callout wasn't working properly (timeout).

    Now, I'm running a real SMTP relay without any firewall rule and everything is working perfectly!

    Cheers,

    Nicolas