Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Email flow to Exchange server stops

Sophos XGS 2300 running 20.0.1

Internal exchange server

DNAT rule allowing passthru of SMTP traffic to the exchange server. ports 25,465,587.

From time to time we stop receiving email. to fix, we reboot the sophos firewall.

When it stops working, I try a telnet connection to port 25 on the email server from outside and get no response.

This happens maybe once every 6 months,

I have another Sophos XGS126 20.0.1 running in MTA-Mode. This has done the same requiring a reboot.

The fact it will work fine for several months before data flow stops would suggest the Sophos rules are setup correctly.

Ideas?



This thread was automatically locked due to age.
Parents Reply Children
  • Hi  ,

    just want to be sure we understand the situation.

    Do I get that right that you don't use neither the legacy mode nor the MTA mode mail proxies on SFOS and your firewall should forward all SMTP traffic directly to your backend Exchange server?

    Thank you,

    Janos 

  • I have one Sophos with a business rule delivering ports 25, 465 and 587 to the internal exchange server. The second unit is acting as an MTA.

    Email is the first service that users notice "We've not received any email for a while". Try using putty from external and unresponsive. Try accessing browser-based services like OWA or ECP and neither work.

    Connect to the Sophos and reboot - everything starts working again.

    This happens maybe once every 6-9 months. The sophos gets rebooted for firmware updates about 2 weeks after an update is released.