Mail and webserver issues under XGS136W

Hi community 

Please i have this issue for our customers, we migrated from UTM9 under SG135 series to new series XGS136W

before we start you can find current configuration.

  • Appliance are connected to ISP Modem (Router) via port 2(WAN)
  • Port 1 is connected to LAN, no DMZ configured.
  • Customer App embedded in Webserver wish can be access via a domain name outside LAN.
  • Server containing Microsoft Exchange 2013 for mails.
  • Server for AD and DC.

I used the following configurations:

  • Creating DNAT for webserver on the top(Rule 1)
  • Creating DNAT for Exchange server (Rule 2)
  • Using sophos MTA for mail agent

Bellow the issues:

In configuration above, users can access webserver outside LAN without any issue, but they can't send or receive emails. (emails works fine when they are connecting locally)

When changing DNAT order webserver become inaccessible while emails works fine.

Any suggestions?

Edited TAGs
[edited by: Erick Jan at 12:41 PM (GMT -8) on 21 Feb 2024]