Hi,
I'm using a Sophos UTM 9 in Bridge Mode and try to activate the full transparent mode for SMTP.
The target is to scan all incoming SMTP traffic on Port 25 for SPAM and to filter it before it gets into the network.
Unfortunately I fail with this :-/ Maybe somebody has an idea what I did wrong.
As mentioned the Sophos SG105 is running in bridged mode. Everything else like Firewall, IPS and so on is working as I'd expect it.
I activated the SMTP Proxy mode in simnple mode, added my e-mail domains that I expect to get into my network and the Exchange server that is there.
The Exchange server is added as static host in the host list.
In the last tab I activated the transparent mode, since its description seems to be what I want the Sophos to do. It listens and scans all traffic on Port 25.
Everything else I left as default.
When I receive mail now, it is rejected and I don't seem to be able to figure out why that is.
Somewhere in the manual I found that it is important to make sure the DNS is working correctly on Sophos but that works flawless as far as I can tell
Maybe somebody can shed some light on this since I'm rather clueless.
I activated the debug mode for SMTP and this is what I get for all incoming mail.
13810 Connection request from 13.67.59.89 port 5432
13810 LOG: smtp_connection MAIN
13810 SMTP connection from [13.67.59.89]:5432 (TCP/IP connection count = 1)
13810 search_tidyup called
13810 1 SMTP accept process running
13810 Listening...
30491 sender_fullhost = [13.67.59.89]:5432
30491 sender_rcvhost = [13.67.59.89] (port=5432)
30491 Process 30491 is handling incoming connection from [13.67.59.89]:5432
30491 host in host_lookup? yes (matched "*")
30491 looking up host name for 13.67.59.89
30491 DNS lookup of 89.59.67.13.in-addr.arpa (PTR) gave HOST_NOT_FOUND
30491 returning DNS_NOMATCH
30491 IP address lookup using gethostbyaddr()
30491 IP address lookup failed: h_errno=1
30491 LOG: host_lookup_failed MAIN
30491 no host name found for IP address 13.67.59.89
30491 sender_fullhost = [13.67.59.89]:5432
30491 sender_rcvhost = [13.67.59.89] (port=5432)
30491 set_process_info: 30491 handling incoming connection from [13.67.59.89]:5432
30491 host in host_reject_connection? no (option unset)
30491 host in sender_unqualified_hosts? no (option unset)
30491 host in recipient_unqualified_hosts? no (option unset)
30491 host in helo_verify_hosts? no (option unset)
30491 host in helo_try_verify_hosts? no (option unset)
30491 host in helo_accept_junk_hosts? no (option unset)
30491 using ACL "acl_check_connect"
30491 processing "drop"
30491 check condition = 0
30491 drop: condition test failed in ACL "acl_check_connect"
30491 processing "accept"
30491 accept: condition test succeeded in ACL "acl_check_connect"
30491 SMTP>> 220 [myMXdomain] ESMTP ready.
30491 Process 30491 is ready for new message
30491 smtp_setup_msg entered
30491 SMTP>> 421 [myMXdomain] lost input connection
30491 LOG: smtp_connection MAIN
30491 SMTP connection from [13.67.59.89]:5432 lost (error: Connection reset by peer)
30491 search_tidyup called
13810 child 30491 ended: status=0x100
13810 normal exit, 1
13810 0 SMTP accept processes now running
13810 Listening...
Thanks
Sophie
This thread was automatically locked due to age.