Solved

SonicWALL open Port 25 to specific external IPs only

Posted on 2011-02-25
6
2,160 Views
Last Modified: 2012-05-11
Hey everyone.

I am having some trouble configuring the SonicWALL to only accept SMTP traffic from a few external IP addresses. We have Hosted Websense which removes spam for us before sending it along to our server.

I created Address Objects on the SonicWALL with the proper network addresses. I then went to Access Rules on the firewall and enabled these address objects to the WAN interface.

Are these supposed to be pointing to the mail servers internal or external interface? I tried both and neither would work.

Attached 3 pics of the setup config... what have i done wrong?
sonicwall.jpg
sonicwall2.jpg
sonicwall3.jpg
0
Comment
Question by:tamaneri
6 Comments
 
LVL 9

Expert Comment

by:tjdabomb
ID: 34983876
do you also have address objects for websense 2, 3, and 4?  Is there a service in the Sonicwall for "SMTP Receive email"??
0
 
LVL 3

Author Comment

by:tamaneri
ID: 34984128
I don't see a "SMTP Receive Email" setting.

I see:

SMTP (Anti-Spam Inbound Port)
SMTP (Send E-mail)

I tried it first with Anti-Spam Inbound Port and it wouldn't work either.

I added both SMTP's to the services for my exchange server (see pic), but that opens port 25 to everyone from what I can tell.

Also attached snapshots for the other websense connectors
sonicwall4.jpg
sonicwall5.JPG
sonicwall6.JPG
sonicwall7.JPG
0
 
LVL 9

Expert Comment

by:tjdabomb
ID: 34984425
i am not entirely familiar with websense, but, is it possible that you need a pop3 connection to the websense in order to get the email to your local exchange box?  Kinda like your exchange acts like Outlook and needs to pop3 mail inbound from websense.
0
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 33

Accepted Solution

by:
digitap earned 250 total points
ID: 34986017
your best bet to get this to work properly is to run the public server wizard.  run it using smtp as your service.  then, create the address objects that represent the public IPs that you want to explicitly allow ingress (if you have not already), create an address group and add those objects to the group. then, go back to the firewall access rule wan > lan and edit the source using the address group.  you'll want to edit the ingress/egress NAT policies with the group as well.  i think original source for ingress and translated destination for egress.
0
 
LVL 6

Assisted Solution

by:caskrist
caskrist earned 250 total points
ID: 34987982
Yes digitap is right run the public server wizard, but it is sufficient to only edit the firewall rule (WAN -> LAN) and change the source to your address group e.g. Websense.
(BTW you can create a group of address objects, put all the ip's and/or ranges in one group and use this group as a source(no need for websense1, websense2 etc) )
0
 
LVL 6

Expert Comment

by:caskrist
ID: 35031205
Thanks for the points, good luck.
0

Featured Post

Gigs: Get Your Project Delivered by an Expert

Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
This article lists the top 5 free OST to PST Converter Tools. These tools save a lot of time for users when they want to convert OST to PST after their exchange server is no longer available or some other critical issue with exchange server or impor…
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates…

805 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question