This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall blocking


I have added a Network Definitions group called "Blocked Attackers" and added several IP addresses and IP subnets.
I added a firewall rule (on position 1) with the following settings:

Sources: Blocked Attackers
Services: Any
Destinations: Any
Action: Drop (also tried reject)

The rule is enabled but I still see the IP address appear on the SMTP proxy trying to authenticate.

Am I missing something here?

This thread was automatically locked due to age.
Parents Reply
  • There is no DNAT rule (in SMTP config it's just relaying mail to the Exchange server).
    "Authenticated users can relay" is enabled indeed.

    1) Don't really know what you mean, only the Exchange server is relaying outgoing mail to the UTM
    2) They open their mailbox via OWA or Exchange ActiveSync on mobile phones
