<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Email Protection auto generated MTA Firewall Rule</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/147965/email-protection-auto-generated-mta-firewall-rule</link><description>Hi, I can&amp;#39;t seem to find a clear answer as to why the auto generated MTA firewall rule is needed. As I understand it, in MTA mode emails are being &amp;#39;handled&amp;#39; by the firewall rather than just traffic passing through it, so access should be controlled by</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Email Protection auto generated MTA Firewall Rule</title><link>https://community.sophos.com/thread/548578?ContentTypeID=1</link><pubDate>Tue, 12 Nov 2024 17:33:57 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:728cf220-6455-41a3-bf73-3f254aa5ac95</guid><dc:creator>LuCar Toni</dc:creator><description>&lt;p&gt;Essentially we are using the MTA rule to give the Exim (MTA Service) a way to communicate through the system.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This rule is used for allowing the own traffic for email traffic (out and inbound).&lt;/p&gt;
&lt;p&gt;You should not delete it, as it might corrupt your email traffic, as the firewall cannot find a rule to allow outgoing / inbound email traffic.&lt;/p&gt;
&lt;p&gt;You can modify the rule, if you want to, the core principle, it should still exists. I also saw people disable the rule (not deleting) and it is fine.&lt;/p&gt;
&lt;p&gt;Essentially the rule transform the firewall to perform transparent SMTP scanning as well, by forwarding the traffic (port25) through the firewall to the MTA.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Email Protection auto generated MTA Firewall Rule</title><link>https://community.sophos.com/thread/548577?ContentTypeID=1</link><pubDate>Tue, 12 Nov 2024 17:24:20 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:b22717bf-419c-4a8e-8ce9-2c9177feda5a</guid><dc:creator>Vivek Jagad</dc:creator><description>&lt;p&gt;Hi &lt;a href="/members/jtaylor"&gt;jtaylor&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;br /&gt;&lt;br /&gt;The Auto added firewall policy for MTA(Mail Transfer Agent), is used to protect mail servers which are hosted internally in a network and require protection. This rule does not mean it will allow any traffic from any source.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Email Protection auto generated MTA Firewall Rule</title><link>https://community.sophos.com/thread/548575?ContentTypeID=1</link><pubDate>Tue, 12 Nov 2024 16:44:08 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:3d058d32-b463-4f55-bca9-051be0c91e1a</guid><dc:creator>jtaylor</dc:creator><description>&lt;p&gt;Hi Vivek, thanks for your reply, however I&amp;#39;m afraid I&amp;#39;m no clearer about why the rule is needed.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Email Protection auto generated MTA Firewall Rule</title><link>https://community.sophos.com/thread/548519?ContentTypeID=1</link><pubDate>Mon, 11 Nov 2024 15:40:46 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:37c76646-2b79-4dd0-9023-b457d1284d24</guid><dc:creator>Vivek Jagad</dc:creator><description>&lt;p&gt;Hi &lt;a href="/members/jtaylor"&gt;jtaylor&lt;/a&gt;&amp;nbsp;,&lt;br /&gt;&lt;br /&gt;Thank you for reaching out to the&amp;nbsp;community, you can limit services to emails services...&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>