This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Draytek -> Sophos UTM9 -> Hmailserver forward problems.

Hello,

I have a DrayTek Vigor 2860 Router (192.168.0.1) with 2 WAN ports. And have an internal mailserver (HMailserver) on 192.168.0.36
The ports forwards thats will be used are 25, 465, 143 forwarding to the mailserver. For that it works fine.

We want to use Sophos UTM9, because from there are a lot of hacking attempts to Hmailserver from country's that we do not communicate with. Now we want to use sophos as a country filter.

We installed Shopos with VirtualBox, the WAN IP 192.168.0.38 and the LAN IP is 192.16.0.39

We make a NAT Rule (DNAT, Any -> Email Messasing -> Hmailserver) and Destination HMailserver and automatic firewall rules.

Draytek ports forwards changed to 192.168.0.38

But now we don't received any mails. And the diagnostic tool in Hmailserver give a poort 25 error, whats tells us that port 25 in not available. So Sophos wont accept this.


Now is the question: What do we do wrong?



This thread was automatically locked due to age.
Parents
  • Hi, Robert, and welcome to the UTM Community!

    From your description, I'll guess that your configuration violates the second item in #3.1 in Rulz.

    I don't know what your topology looks like, but I'll guess that your solution will be to delete the LAN interface and then bridge that NIC on the WAN interface.  You will still need a firewall rule like 'WAN (Network) -> Any WAN (Network) : Allow'.

    Any better luck now?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Hi, Robert, and welcome to the UTM Community!

    From your description, I'll guess that your configuration violates the second item in #3.1 in Rulz.

    I don't know what your topology looks like, but I'll guess that your solution will be to delete the LAN interface and then bridge that NIC on the WAN interface.  You will still need a firewall rule like 'WAN (Network) -> Any WAN (Network) : Allow'.

    Any better luck now?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data