CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-05
Junior Member
 
Join Date: 2007-10-10
Posts: 22
Rep Power: 0
technick22 has an average reputation (10+)
Default smtp problem

I got a weird smtp problem...

I created a nat
Any - External IP - SMTP - Original - Internal IP - SMTP
I created a rule
Any - External IP - SMTP - Allow

When i telnet from within my network to the mail server on port 25 everything works as it should. "220 SMTP Proxy Server Ready"
When i try the same thing from outside, it doesn't. It looks like it connects, but no output in telnet window.
I don't even get any log entry showing me a connection was attempted in Tracker.

I also created another nat rule to the same box (which is required)..

Any - External IP - 12321 - Original - Internal IP - 12321
I created a rule
Any - External IP - 12321 - Allow

This works fine from both inside and outside.
Also being logged fine within Tracker

Note that 12321 and SMTP are part of the same policy rule.

I have tried with both an IP that is being proxy-arped and another which isn't.
SMTP just doesn't want to connect.

ISP is not blocking SMTP

Am i missing something?
Reply With Quote
  #2 (permalink)  
Old 2007-12-05
Member
 
Join Date: 2005-09-23
Posts: 75
Rep Power: 4
donshoutarp has an average reputation (10+)
Default Re: smtp problem

Quote:
Originally Posted by technick22 View Post
I got a weird smtp problem...

I created a nat
Any - External IP - SMTP - Original - Internal IP - SMTP
I created a rule
Any - External IP - SMTP - Allow

When i telnet from within my network to the mail server on port 25 everything works as it should. "220 SMTP Proxy Server Ready"
When i try the same thing from outside, it doesn't. It looks like it connects, but no output in telnet window.
I don't even get any log entry showing me a connection was attempted in Tracker.

I also created another nat rule to the same box (which is required)..

Any - External IP - 12321 - Original - Internal IP - 12321
I created a rule
Any - External IP - 12321 - Allow

This works fine from both inside and outside.
Also being logged fine within Tracker

Note that 12321 and SMTP are part of the same policy rule.

I have tried with both an IP that is being proxy-arped and another which isn't.
SMTP just doesn't want to connect.

ISP is not blocking SMTP

Am i missing something?
Try creating another nat
Internal IP - Any -Any External IP - Original - Any.
Reply With Quote
  #3 (permalink)  
Old 2007-12-06
Senior Member
 
Join Date: 2007-06-04
Posts: 1,072
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: smtp problem

Try connecting with something like Outlook Express and configure the IP as it's SMTP Server and see if that connects.

Also configure the outbound service as well.
Reply With Quote
  #4 (permalink)  
Old 2007-12-06
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: smtp problem

Are you sure you don't get logs? That is VERY strange, since everything works fine for the other port, you would expect to see at least a drop or something for the smtp traffic.

Are you logging implied rules? If not I think you should tick it, push the policy and try the access again. Then check the logs, making sure you don't have any filters and select the "All records option".
Reply With Quote
  #5 (permalink)  
Old 2007-12-06
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: smtp problem

From the gateway:

fw monitor -e 'accept dport=25 and (dst=<external ip> or src=<internal ip>);'

This should tell you where the packets are going. If my syntax is off, the "fw monitor" info posted on http://www.cpug.org/check_point_resources.htm is very good.
Reply With Quote
  #6 (permalink)  
Old 2007-12-07
Junior Member
 
Join Date: 2007-10-10
Posts: 22
Rep Power: 0
technick22 has an average reputation (10+)
Default Re: smtp problem

ok i got it to work.

another question though....

in my mail headers the IP mentioned is the external IP of my firewall.

I want this IP to be the public IP of my mail server

I am using a proxy-arped IP. Do i need to use a non-proxy-arped IP?
Or do i need to configure an outgoing NAT?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 16:05.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0