Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Send emails to Exchange Online via Sophos XG

Hello,

we have the following problem: 

Three of our server / applications do not support OAuth for the moment, so we need an locally smtp server inside our network.

For the moment we use simple postfix, authenticated users only from specific internal IPs can send e-mails over these server. We added our public ip to spf record, added dmarc and dkim for these server.

With these "workaround" we can send mails on both ways, the applications which support OAuth sends directly to Exchange Online, applications which doesnt support OAuth send to these postfix. 

The postfix-server OS will go EOL next months, so we have the idea to use the Sophos XGS as these "outgoing mailserver". Incoming mails are feteched directly from Exchange-Online (we have EOP P2 activated). On Sophos XG we have XStream Protection activated.

Now my question, is it smart to setup the XG as outgoing e-mail server which send all the outgoing mails overExchange online and then to the final recipient? 

For setup these is the tutotial -> https://docs.sophos.com/nsg/sophos-firewall/18.5/Help/en-us/webhelp/onlinehelp/AdministratorHelp/Email/HowToArticles/EmailMicrosoftO365Setup/index.html the right one?



Edited TAGs
[edited by: Erick Jan at 11:31 AM (GMT -7) on 11 Jul 2024]
Parents
  • XGS doesn't have a full-fledged mailserver, it's only an MTA, or a proxy, depending on the mode you use.

    So you need something else to solve your problem. Why not trying to adapt your Mcrosoft tenant's settings? Maybe using a "connector" like we use it for MFP could work?

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • XGS doesn't have a full-fledged mailserver, it's only an MTA, or a proxy, depending on the mode you use.

    So you need something else to solve your problem. Why not trying to adapt your Mcrosoft tenant's settings? Maybe using a "connector" like we use it for MFP could work?

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

Children