Solved

SonicWall NAT

Posted on 2014-03-07
6
363 Views
Last Modified: 2014-03-10
Hello Experts!

I have a working NSA2400 with failover (ATT & Comcast).

All my inbound mail flows via ATT (X1) and outbound via Comcast (X5). I would like to have outbound mail also flow via (X1) instead of going through the other NAT on X5.

How can that be adjusted?

Thanks much!

Marek
0
Comment
Question by:maredzki
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
  • 2
6 Comments
 
LVL 15

Assisted Solution

by:Perarduaadastra
Perarduaadastra earned 100 total points
ID: 39913736
Just set an outbound rule for SMTP traffic to go out on the X1 interface.

However, if you're running your own mail server you will need to adjust your MX records to include the X1 public IP address, or you'll find that your mailserver gets star billing on numerous RBLs.
0
 
LVL 8

Accepted Solution

by:
N-W earned 400 total points
ID: 39916581
This is more of a routing question because the Sonicwall automatically creates the NAT rules for WAN connections when you initially set them up. All you should need to do is add a static route for the X1 interface.

Login to your management interface, go to Network --> Routing and create a new entry with the following details:

Source: (Your mail server)
Destination: Any
Service: SMTP
Gateway: X1 Default Gateway
Interface: 1
Metric: 1
Disable route when the interface is disconnected: Checked

This will make all outbound SMTP go through X1 (ATT) and will still allow outbound SMTP through X5 (Comcast) in case the X1 WAN link is down.

As Perarduaadastra has mentioned, you will need to change DNS records but this should be a PTR record, not MX. You'll need to contact your ISP for them to change the PTR for your public IP address to something like "mail.mydomain.com".
0
 
LVL 2

Author Closing Comment

by:maredzki
ID: 39917796
Thanks to both of you for the answer.

Marek
0
VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

 
LVL 2

Author Comment

by:maredzki
ID: 39918398
N-W, in your notes about
Interface: 1
, should that actually say X1?

Marek
0
 
LVL 8

Expert Comment

by:N-W
ID: 39918920
Yes, that should say X1.
0
 
LVL 15

Expert Comment

by:Perarduaadastra
ID: 39918921
N-W, I stand corrected. I should have indeed said that the PTR record needs to be updated, not the MX one.
0

Featured Post

Ready to trade in that old firewall?

Whether you need to trade-up to a shiny new Firebox or just ready to upgrade from whatever appliance you're using now, WatchGuard has the right appliance for you! Find your perfect Firebox today with appliance sizing tool!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
Network traffic routing plays key role in your network, if you have single site with heavy browsing or multiple sites, replicating important application data from your Primary Default Gateway ,you have to route your other network traffic from your p…
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…
Suggested Courses

630 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question