Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

MTA with multiple alias IP does not work as expected

Hi Everyone

We setup MTA according to this URL:

https://docs.sophos.com/nsg/sophos-firewall/20.0/help/en-us/webhelp/onlinehelp/AdministratorHelp/Email/HowToArticles/EmailSetupMTAModeWithMultipleWANPortsOrAliasIPAddresses/index.html#change-the-route-precedence

this will work if traffic is sent from LAN to WAN but does not apply to system generated traffic. The only way that works is to use:

set advanced-firewall sys-traffic-nat add destination 0.0.0.0 snat-ip <alias ip>

which uses the specified alias ip for ALL system generated traffic which we dont want.

What can we do?



Added TAGs
[edited by: Raphael Alganes at 11:59 PM (GMT -7) on 21 Jul 2024]
Parents Reply Children