| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Hi all, Our Messaging Platform - Exchange 2000 Firewall - CheckPoint NGX We are unable to send e-mail to a sepcific domain, following is the error (Error-1) we receive on every attempt from our Exchange Server. Upon consulting with target Domain Tech Support, they think its their antispam software rejecting our mails and the reason being, that our SMTP server claims to be a different host (CheckPoint) as indicated in the following message (Error-2) discovered on DNSREPORTS.com How can I configure my CheckPoint Firewall to disable this ?? and do i expose my exchnage Server by doing so ?? Error-1 The following recipient(s) could not be reached: 'support@cse.ca' on 9/1/2006 9:14 AM There was a SMTP communication problem with the recipient's email server. Please contact your system administrator. <myhost.mydomain.com #5.5.0 smtp;554 sorry, your envelope sender is in my badmailfrom list (#5.7.1)> Error-2 Error Message on DNSreports>>>>> WARNING: One or more of your mailservers is claiming to be a host other than what it really is (the SMTP greeting should be a 3-digit code, followed by a space or a dash, then the host name). If your mailserver sends out E-mail using this domain in its EHLO or HELO, your E-mail might get blocked by anti-spam software. This is also a technical violation of RFC821 4.3 (and RFC2821 4.3.1). Note that the hostname given in the SMTP greeting should have an A record pointing back to the same server. Note that this one test may use a cached DNS record. myhost.mydomain.com claims to be invalid hostname 'CheckPoint': 220 CheckPoint FireWall-1 secure ESMTP server Thanks, Sanjeev |
| |||
| Changing the SMTP banner "Check Point FireWall-1 SMTP Security Server". http://secureknowledge.checkpoint.co...292559.2556893 From Policy properties >Security Servers, enter the SMTP Welcome Message or the path to a file containing the welcome message. Note that you have to recompile and reinstall the Security Policy after making this change Last edited by kva.kva; 2006-09-02 at 00:55. |
| |||
| Also you may need to add reverse dns record for firewall external IP address into your DNS server. Some anti-spam softwares may lookup reverse dns record for IP address which mail comes from. |
![]() |
| Thread Tools | |
| Display Modes | |
| |