Re: With authentication off the server denies relaying mail..

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Michael J.L.. Thomas (MThomas_at_shindengen.com)
Date: 03/25/04


Date: Thu, 25 Mar 2004 12:37:24 -0800

I'm not overly familiar with Sonic Firewalls
But if your not using it to filter spam or content filtering of email, then
you can probably just open port 25

Just make sure proxying of SMTP (port 25) is turned off.

Open the ports using one of the following methods:

-Either-
>From Internal = * (any) -to-> External = * (any)
-or-
>From Internal = * (any) -to-> External = <your SMTP server IP>

To find your SMTP server IP if you don't know it try opening the command
prompt and typing "ping <SMTP server named address> and hit enter it should
display the ip for you

An advantage of mapping only to your mail server on port 25 is that it will
block most virus traffic leaving your network should a computer be infected.
If you check your server logs you even be able to identify the infected
machine based on the deny packets and ip address of sender.

Most viruses do not use the default mail server because they direct send
using a built in SMTP engine, there by by-passing your virus protection at
the server level.

Another way might be if you are able to add valid headers to the firewall,
this assumes you can see what headers are being blocked in the first place.

>On 3/25/04 12:14 PM, in article 10b2101c412a5$c30bf0e0$a601280a@phx.gbl,
>"anonymous@discussions.microsoft.com" <anonymous@discussions.microsoft.com>
>wrote:

> Hi,
>
> Looks like that is the problem, could you help me find
> what do I need to change on my firewall, its a sonicwall?
> Mail is going in and out, but i'm sure the headers are not.
>
>
>> -----Original Message-----
>> Are you connnecting through a firewall, if so make sure
>> the firewall is not breaking the headers, this can occur
>> easily if its using SMTP proxying, I had a similar issue
>> with a watchguard firewall....yesterday :-}
>>
>> Anti-Virus apps such as Sysmantec can break it as well.
>>> -----Original Message-----
>>> I did, nothing listed there.
>>>
>>>
>>>> -----Original Message-----
>>>> Yes and I get the following error.
>>>>
>>>> Exchange Account" does not recognize any of the
>>>> authentication methods supported by Entourage. To send
>>>> mail, try disabling SMTP authentication in the account
>>>> settings or talk to your administrator.
>>>>
>>>> An unknown error (5530) occurred
>>>>
>>>> HELP!!
>>>>> -----Original Message-----
>>>>> I'm running
>>>>>
>>>>> OS x
>>>>> Entourage x
>>>>>
>>>>> inbound mail is fine, when i try to reply to the
>>> senders,
>>>>> i get the unable to relay error.
>>>>>
>>>>> any help would be appreciated.
>>>>>
>>>>>
>>>>>
>>>>> .
>>>>>
>>>> .
>>>>
>>> .
>>>
>> .
>>



Relevant Pages

  • Re: CEICW fails at firewall config
    ... Do you or do you not have ISA 2000 or ISA 2004 installed on the SBS server? ... Do you have 2 NICs in the SBS? ... CEICW fails on firewall configuration every time. ... >>> Call to Creating the protected networks access rule returned ok. ...
    (microsoft.public.windows.server.sbs)
  • Re: Recycler security issues on IIS server
    ... > latest upates to the server. ... > like to see the server put behind our firewall, ... other software, install all patches, IISlockdown, URLscan, use the correct ... the procedures you follow may vary depending on your security needs. ...
    (microsoft.public.inetserver.iis.security)
  • Re: ISA SERVER NOT STARTING
    ... I delete the nat/basic firewall and stop and started the RRAS an tried to ... There were no critical events in the DNS Server Log in the last 24 hours. ... An error occurred during logon ... Caller User Name: - ...
    (microsoft.public.windows.server.sbs)
  • Re: For Microsoft Partners and Customers Who Cant Download or Access
    ... to reconfigure the firewall, but to use a static IP on your client ... and to make sure that the DNS server entries on the client are ... Microsoft for msdn2.microsoft.com. ... use a static IP and set the DNS server addresses to the DNS ...
    (microsoft.public.dotnet.general)
  • RE: Is this as bad as it seems?
    ... The network being protected by the router or firewall is still vulnerable to ... > circumvented - the administrator has explicitly allowed HTTP traffic on ... this exploit has the effect of allowing the attacker to send *INBOUND* HTTP ... The HTTP server (located on the internal network or anywhere else that is ...
    (Security-Basics)