Re: Turn Firewall Off ?

From: Mark (Mark_at_ecc-limited.nildram.co.uk)
Date: 05/12/04


Date: Thu, 13 May 2004 00:17:28 +0100

Kevin

First off thanks for the interest.

The problem stems from my inability to receive Email via SMTP.

I have installed SBS2003 Prem edition with a domain name with a .com tld.
During the "connect to internet" I specified that "MAIL" should be let
through the firewall which should allow me to receive Email via SMTP. I can
send Email out and internally no problem.

On another forum I found a hit that indicated the Firewall was blocking the
traffic. I then sought to confirm whether this was a fact in my case.
Someone suggested that I perform a Network Trace on the NIC, which I did. I
have used www.dnsreport.com to test connection and issuing "telnet
servername.domainname.com 25" to connect to my server. Internally the TelNet
works and externally it doesn't. Looking at my router log I can see a port
25 request come in and translated to the private IP address for my SBS
internet connection.

The Network Trace shows the appropriate IP address of the requester and port
25/SMTP entries. But that is the end of it. The trace has lots of
information in but I don't have the skill/information to translate this into
step-by-step event path.

My next step, where you came in, was to disable the Firewall to confirm
whether he was the problem and then try to fix it. The guy who found the
Firewall has an issue indicated that numerous parms to allow port 25 inbound
to work had to be changed. The only mention I can see is in the "Connect to
Internet" script. Hence my question.

Is there any log/trace facility for the Firewall that allow me to see what
it is doing. Can't see it in the event log or the System32\LogFiles
directory

There is course potential that I have mis-configured something, I'm no MCSE,
or perhaps the DNS side of things is preventing the correct routing but the
DnsReport site report looks ok. I seem to have the appropriate A and MX
records to direct mail to my server and my router confirms there is SMTP
inbound traffic.

Any other ideas welcome.

Regards

Mark

"Kevin Weilbacher" <kweilbacMVP@gte.net> wrote in message
news:eYK6GTGOEHA.3452@TK2MSFTNGP10.phx.gbl...
> Before trying to break something that may be working, can you describe the
> exact problem you are having with Exchange?
>
> --
> Kevin Weilbacher [SBS-MVP]
> "The days pass by so quickly now, the nights are seldom long"
>
>
>
> "Mark" <Mark@ecc-limited.nildram.co.uk> wrote in message
> news:40a24bbc$0$6329$65c69314@mercury.nildram.net...
> > I have a problem with receiving Email via SMTP and want to investigate
the
> > Firewall.
> >
> > 1) Outside of the "Connect to Internet" gui where can I find what ports
> the
> > Firewall has open or blocked ?
> > 2) Is it possible to turn some type of logging on or run a utility for
the
> > firewall; so that I can see when a port request is blocked or allowed
> > through ?
> >
> > Thanks in advance
> >
> > Mark
> >
> >
> >
>
>



Relevant Pages

  • Re: "Offenes" SMTP-Relay mal anders
    ... Port 25/tcp jedes am Internet angeschlossenen Hosts fuer SMTP reserviert ... marmelade von genau diesem brot eine unerwuenschte handlung sei. ...
    (de.comp.security.misc)
  • Re: [Firewalls] Checkpoint FW-1 - Static NAT
    ... These services perform port mapping. ... destination port and IP address of a connection can be changed. ... After installing the new policy on the target Firewall Module, ... One to the internet, and the other to ...
    (comp.security.firewalls)
  • Re: Inaccessible Port 80 - Pentest
    ... donot think a firewall would block be blocking. ... A mixture of layer 3 port filtering to restrict you to port 80 would seem to ... Internet, open one port on it and then block it from public use? ...
    (Pen-Test)
  • Re: [Newbie alert!] Is the Linksys BEFSX41 hardware Firewall/router a "real" firewall?
    ... there is very little that a real firewall appliance will ... ALL inbound and outbound traffic in real time - a simple KVM switch will ... outbound SMTP then it can spam all it wants. ... Private Ports in some versions - where you can list port ranges to block ...
    (comp.security.firewalls)
  • Re: "Offenes" SMTP-Relay mal anders
    ... "well-known port", reserviert fuer SMTP. ... In der Umgebung "Internet" ist Port 25/tcp fuer SMTP reserviert. ...
    (de.comp.security.misc)