Have a 220 running latest (9.4) version of UTM 9. Have email protection. It listens across all interfaces. That sounds like a really silly method of doing that to me, but that's how it works.
It fails PCI scans because the certificate is a self-signed certificate. A solution is not to "buy a proper certificate" because in this particular case there are multiple domains behind the firewall. For which would the customer buy a cert?
One solution would be to block or disable SMTP ports across everything but the main interface. Sophos support tells me you can't do that.
Certainly there is a way to do this otherwise this UTM 220 gets tossed.
Thanks.
This thread was automatically locked due to age.