Solved

SonicWALL open Port 25 to specific external IPs only

Posted on 2011-02-25
6
2,164 Views
Last Modified: 2012-05-11
Hey everyone.

I am having some trouble configuring the SonicWALL to only accept SMTP traffic from a few external IP addresses. We have Hosted Websense which removes spam for us before sending it along to our server.

I created Address Objects on the SonicWALL with the proper network addresses. I then went to Access Rules on the firewall and enabled these address objects to the WAN interface.

Are these supposed to be pointing to the mail servers internal or external interface? I tried both and neither would work.

Attached 3 pics of the setup config... what have i done wrong?
sonicwall.jpg
sonicwall2.jpg
sonicwall3.jpg
0
Comment
Question by:tamaneri
6 Comments
 
LVL 9

Expert Comment

by:tjdabomb
ID: 34983876
do you also have address objects for websense 2, 3, and 4?  Is there a service in the Sonicwall for "SMTP Receive email"??
0
 
LVL 3

Author Comment

by:tamaneri
ID: 34984128
I don't see a "SMTP Receive Email" setting.

I see:

SMTP (Anti-Spam Inbound Port)
SMTP (Send E-mail)

I tried it first with Anti-Spam Inbound Port and it wouldn't work either.

I added both SMTP's to the services for my exchange server (see pic), but that opens port 25 to everyone from what I can tell.

Also attached snapshots for the other websense connectors
sonicwall4.jpg
sonicwall5.JPG
sonicwall6.JPG
sonicwall7.JPG
0
 
LVL 9

Expert Comment

by:tjdabomb
ID: 34984425
i am not entirely familiar with websense, but, is it possible that you need a pop3 connection to the websense in order to get the email to your local exchange box?  Kinda like your exchange acts like Outlook and needs to pop3 mail inbound from websense.
0
NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

 
LVL 33

Accepted Solution

by:
digitap earned 250 total points
ID: 34986017
your best bet to get this to work properly is to run the public server wizard.  run it using smtp as your service.  then, create the address objects that represent the public IPs that you want to explicitly allow ingress (if you have not already), create an address group and add those objects to the group. then, go back to the firewall access rule wan > lan and edit the source using the address group.  you'll want to edit the ingress/egress NAT policies with the group as well.  i think original source for ingress and translated destination for egress.
0
 
LVL 6

Assisted Solution

by:caskrist
caskrist earned 250 total points
ID: 34987982
Yes digitap is right run the public server wizard, but it is sufficient to only edit the firewall rule (WAN -> LAN) and change the source to your address group e.g. Websense.
(BTW you can create a group of address objects, put all the ip's and/or ranges in one group and use this group as a source(no need for websense1, websense2 etc) )
0
 
LVL 6

Expert Comment

by:caskrist
ID: 35031205
Thanks for the points, good luck.
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Marketers need statistics and metrics like everybody else needs oxygen. In this article we explain how to enable marketing campaign statistics for Microsoft Exchange mail.
Read this checklist to learn more about the 15 things you should never include in an email signature.
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question