This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

outbound nat

hi

i have a utm9 with 2 interfaces

interface 1 192.168.4.170, going out via 192.168.4.1, so far so good. everything going out via 4.170 works just fine

interface 2 192.168.82.170 going out via 192.168.82.1 (policy route). when i'm pinging from interface 2, everything is ok and going out via 192.168.82.1 (using sophos tools from inside the utm)

but when i'm sending packets from any host in 192.168.82.0/24, the traffic still going out via interface 1

i've done a dnat, but i must be doing something wrong

 

thank you 

 



This thread was automatically locked due to age.
Parents Reply Children
  • i have 2 email servers behind the utm

    i need 1 of them to go out via wan1

    and the other via wan2

     

    so both services are smtp, but the source is diferent 

    maybe my problem is the smtp proxy module? maybe it's ignoring nat and pushing smtp out only with the default gateway of the entire utm?

  • OK. I think your problem could be solved by using a SNAT Rule. These are created under Network Protection -> NAT.
    I'll show you one example which should fit your needs.

    Put in the source one of your servers. The service and destination should fit.
    Now specify in change source the public IP you want that server to send.
    Please let me know if this is working for you.

    Best regards

    Alex

    -

  • thank you

    no, the traffic still flows via the main public ip

    i'm guessing it has something to do with the smtp proxy

  • Then don't use the smtp proxy. The SMTP Proxy is an email server by itself. See ISO/OSI for differentiating SMTP or TCP. I think I don't have any further hints, so I'm out of this thread, sorry.

    Good luck

    Alex

    -

  • If both mail servers are relaying outbound mail though the STP Proxy, they will both send from the IP of "External (Address)."  I'm certain there a suggestion to allow different public IPs and different interface in Ideas, but I don't think that on the horizon.  Your best bet is to combine Alex' suggestions and use a Multipath rule binding non-proxied traffic to another interface for one server.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA