Link to home
Start Free TrialLog in
Avatar of Silas
Silas

asked on

SonicWall Firewall question regarding email

I have a SonicWall firewall appliance.  It is set up to route people out to the Internet using NAT from the External interface's public address.  I also have some other available addresses, so I set up a one-to-one NAT mapping to my Internal email server and then set up an access rule to allow WAN traffic (I presume Internet) to reach the public alias of the email server with SMTP & POP3.  However, email is not coming in.  Is there another way to do this -or have I done it incorrectly?
ASKER CERTIFIED SOLUTION
Avatar of geoffryn
geoffryn

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of jwalsh88
jwalsh88

You need to find out from Sonic Wall when it does NAT.  If it does the NAT before it checks the rulebase then, like geoffryn said you need to setup the rulebase to allow traffic to the internal not external IP address.  This is the opposite of checkpoint, which you have asked alot of questions about, ...for now.  Supposedly, and I have not played with it yet, checkpoints NG product will change NAT from the last thing done to the first.
Avatar of Tim Holman
Check your email server is not covered by the global NAT rule that's letting your users out.  If it is, traffic will be leaving with the firewall's address, not the correct NATted address.  You need an 'anti NAT' rule if this is the case, or to create 2 internal network groups covering IP addresses either side of your email server so that it doesn't get NATted incorrectly.
Yes, Silas as tim holman stated I hope you made sure that your static mapping of the emails public Ip address to the Private Ip address happens before your hiding NAT rule translates the internal Emails address to the external IP address assigned to the Sonic Wall to be used for hide NAting.  I have never worked with Sonic Wall but I would hope it logs the traffic in which case you should be able to look through the logs and see what is happening.
Avatar of Silas

ASKER

yes -Sonic wall uses the private -you set up a public server.