This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

email protection (incoming) for mail server in DMZ (DNAT) with own public IP

UTM 9.702

Hello

I apologize if this email protection related setup question has been answered already elsewhere - I just did not found a answer that seems to suites our setup.

We have an email server behind the UTM in a privat DMZ network and it has its own public IP address. So we do DNAT/SNAT with manual Firewall rules. We want to be processed incoming (only incoming) email by the UTM email protection functionality. We hade configured the incoming manual firewall rules like:

- any to mail-DMZ with: imap, imap SSL, smtp, smtp SSL

This worked so far for normal operation without email protection enabled. Now we have enabled the UTM email protection as following:

 

- Transparent mode : off

- Simple Mode : on

- Listen Interfaces : All interfaces (for the moment)

- Routing|Domains : entred all our domains linke "ourdom.net"

- Routing|Route by : Static host list

- Routing|Host List : mail-DMZ (privat IP in DMZ of mail-server)

 

With this email protection setting we disabled the smtp service in the above firewall rule. Incoming smtp traffic stopped instantly to the mail server (as  exepted) but no incoming smtp traffic was intercepted by the UTM email protection nor routed toward the our mail-server (as the UTM email protection live log shows). So there is a missing part in our setup - I gues the UTM email protection is not "listening" on the public IP of our mail-server, although the email protection is listening on the interface level on all interfaces.
 
Many thanks for any hint. best regards,
 
André


This thread was automatically locked due to age.
Parents Reply Children
No Data