CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Content Security/Security Servers/CVP/UFP
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-09-01
spabbi spabbi is offline
Junior Member
 
Join Date: 2005-10-22
Posts: 3
Rep Power: 0
spabbi has an average reputation (10+)
Default Unable to send e-mail to a SPECIFIC Domain

Hi all,

Our Messaging Platform - Exchange 2000
Firewall - CheckPoint NGX

We are unable to send e-mail to a sepcific domain, following is the error (Error-1) we receive on every attempt from our Exchange Server.

Upon consulting with target Domain Tech Support, they think its their antispam software rejecting our mails and the reason being, that our SMTP server claims to be a different host (CheckPoint) as indicated in the following message (Error-2) discovered on DNSREPORTS.com

How can I configure my CheckPoint Firewall to disable this ??
and do i expose my exchnage Server by doing so ??

Error-1
The following recipient(s) could not be reached:

'support@cse.ca' on 9/1/2006 9:14 AM
There was a SMTP communication problem with the recipient's email server. Please contact your system administrator.
<myhost.mydomain.com #5.5.0 smtp;554 sorry, your envelope sender is in my badmailfrom list (#5.7.1)>



Error-2
Error Message on DNSreports>>>>>

WARNING: One or more of your mailservers is claiming to be a host other than what it really is (the SMTP greeting should be a 3-digit code, followed by a space or a dash, then the host name). If your mailserver sends out E-mail using this domain in its EHLO or HELO, your E-mail might get blocked by anti-spam software. This is also a technical violation of RFC821 4.3 (and RFC2821 4.3.1). Note that the hostname given in the SMTP greeting should have an A record pointing back to the same server. Note that this one test may use a cached DNS record.



myhost.mydomain.com claims to be invalid hostname 'CheckPoint':

220 CheckPoint FireWall-1 secure ESMTP server


Thanks,
Sanjeev
Reply With Quote
  #2 (permalink)  
Old 2006-09-02
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Unable to send e-mail to a SPECIFIC Domain

Changing the SMTP banner "Check Point FireWall-1 SMTP Security Server".
http://secureknowledge.checkpoint.co...292559.2556893

From Policy properties >Security Servers, enter the SMTP Welcome Message or the path to a file containing the welcome message.
Note that you have to recompile and reinstall the Security Policy after making this change

Last edited by kva.kva; 2006-09-02 at 00:55.
Reply With Quote
  #3 (permalink)  
Old 2006-09-06
_d3nx _d3nx is offline
Junior Member
 
Join Date: 2006-04-05
Location: VAN
Posts: 24
Rep Power: 0
_d3nx has an average reputation (10+)
Default Re: Unable to send e-mail to a SPECIFIC Domain

Also you may need to add reverse dns record for firewall external IP address into your DNS server. Some anti-spam softwares may lookup reverse dns record for IP address which mail comes from.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:14.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0