i have currently a Problem with the UTM running on SG450. Every day there is twice a day an E-Mail delay of around 30 Minutes. In those 30 Minutes the UTM is only rejecting SPAM, and not delivering Mails. As soon as the SPAM rejection stops, the Mails are going in and out. Has anyone come across the same Problem or is this a normal behaviour? I opened countless Tickets at Sophos Support, they said to me that "everything is working fine".
What i have already done:
reimaged both nodes
did postgres rebuild ( UTM is working better since then )
created blackhole routes for failed SMTP auth attempts
Hallo and welcome to the UTM COmmunity!
What do you see in the SMTP log for an email that arrives in those 30 minutes but is not delivered?
Cheers - Bob
2021:07:26-11:12:30 fra-31-1 smtpd: SCANNER: 1m7wf0-0004xM-Bn <= email@example.com R=1m7wG5-0004lW-23 P=INPUT S=1348912021:07:26-11:12:30 fra-31-1 smtpd: SCANNER: id="1000" severity="info" sys="SecureMail" sub="smtp" name="email passed" srcip="xxx.xxx.xxx.xxx" from="firstname.lastname@example.org" to="email@example.com" subject=xxxxxxx" queueid="1m7wf0-0004xM-Bn" size="134891"2021:07:26-11:12:30 fra-31-1 exim-out: 2021-07-26 11:12:30 1m7wf0-0004xM-Bn => firstname.lastname@example.org P=<email@example.com> R=static_route_hostlist T=static_smtp H=xx.xx.xx.xx [xx.xx.xx.xx]:25 C="250 Ok"2021:07:26-11:12:30 fra-31-1 exim-out: 2021-07-26 11:12:30 1m7wf0-0004xM-Bn Completed
all Mails are being delivered but with ~30 Minutes delay.
Here is a Screenshot from the Mail Manager, the first Mail that is delivered, is the Log from above(26 Minutes delay). The UTM is only rejecting SPAM for half an hour and then sends all those Mails that are queued:
I'm going to guess that the issue is in the mail server - any luck with that?
Cheers - BobPS The only malware I've gotten in over 10+ years was from an external link to a picture in this forum over 5 years ago. We can't know if that external site is properly protected (I opened your links in a sandbox). In the future, please insert your images directly into the post. Thanks in advance!