{"id":2230,"date":"2013-02-06T15:23:49","date_gmt":"2013-02-06T14:23:49","guid":{"rendered":"http:\/\/blog.campodoro.org\/?p=2230"},"modified":"2013-02-06T15:24:27","modified_gmt":"2013-02-06T14:24:27","slug":"sophos-astaro-utm-limit-listening-ip-addresses-on-smtp-proxy","status":"publish","type":"post","link":"https:\/\/blog.campodoro.org\/?p=2230","title":{"rendered":"Sophos \/ Astaro UTM &#8211; Limit and separate SMTP Proxy IP addresses"},"content":{"rendered":"<p>As a default, Sophos \/ Astaro UTM&#8217;s SMTP Proxy listens on all external IP addresses. Quite annoying if you have an internal mail server that you want to let your external users use for sending (authenticated) emails, since UTM will intercept all SMTP traffic.<\/p>\n<p>Here&#8217;s how I solved that (only works if you have at least 2 public IP addresses).<\/p>\n<p>&#8211; NAT one external public IP address to your internal mail server (so forward at least ports 25, 465, 587; use the IP address that you use for (example) mail.yourdomain.com. In this example I use\u00c2\u00a0<strong>23.37.149.232 (WAN &#8211; FW2)<\/strong><br \/>\n<a href=\"http:\/\/blog.campodoro.org\/wp-content\/uploads\/2013\/02\/Screen-Shot-2013-02-06-at-3.18.07-PM.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2233\" alt=\"NAT to mailserver\" src=\"http:\/\/blog.campodoro.org\/wp-content\/uploads\/2013\/02\/Screen-Shot-2013-02-06-at-3.18.07-PM.png\" width=\"777\" height=\"114\" srcset=\"https:\/\/blog.campodoro.org\/wp-content\/uploads\/2013\/02\/Screen-Shot-2013-02-06-at-3.18.07-PM.png 777w, https:\/\/blog.campodoro.org\/wp-content\/uploads\/2013\/02\/Screen-Shot-2013-02-06-at-3.18.07-PM-300x44.png 300w, https:\/\/blog.campodoro.org\/wp-content\/uploads\/2013\/02\/Screen-Shot-2013-02-06-at-3.18.07-PM-500x73.png 500w\" sizes=\"(max-width: 777px) 100vw, 777px\" \/><\/a><\/p>\n<p>&#8211; enable SMTP proxy on your UTM (your UTM will now listen on all your external public IP addresses)<\/p>\n<p>&#8211; configure SMTP routing to forward MX emails to your internal server<br \/>\n<a href=\"http:\/\/blog.campodoro.org\/wp-content\/uploads\/2013\/02\/Screen-Shot-2013-02-06-at-3.14.21-PM.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2232\" alt=\"SMTP proxy routing\" src=\"http:\/\/blog.campodoro.org\/wp-content\/uploads\/2013\/02\/Screen-Shot-2013-02-06-at-3.14.21-PM.png\" width=\"784\" height=\"333\" srcset=\"https:\/\/blog.campodoro.org\/wp-content\/uploads\/2013\/02\/Screen-Shot-2013-02-06-at-3.14.21-PM.png 784w, https:\/\/blog.campodoro.org\/wp-content\/uploads\/2013\/02\/Screen-Shot-2013-02-06-at-3.14.21-PM-300x127.png 300w, https:\/\/blog.campodoro.org\/wp-content\/uploads\/2013\/02\/Screen-Shot-2013-02-06-at-3.14.21-PM-500x212.png 500w\" sizes=\"(max-width: 784px) 100vw, 784px\" \/><\/a><\/p>\n<p>&#8211; SSH to your UTM and become root<\/p>\n<p>&#8211; with vi, edit this file:\u00c2\u00a0<strong>\/var\/storage\/chroot-smtp\/etc\/exim.conf<\/strong><\/p>\n<p>&#8211; edit this line, remove the # and enter your public IP address to reflect your MX record (like mx.yourdomain.com):<br \/>\n<strong>local_interfaces = 23.37.149.233:81.37.153.126:59.94.132.164<\/strong><br \/>\n(I have 3 SDSL lines on my Sophos UTM box, separate each entry with semicolons)<\/p>\n<p>&#8211; restart your EXIM service:<br \/>\n<strong>\/var\/mdw\/scripts\/smtp restart<\/strong><\/p>\n<p>Check you SMTP Proxy log file, something like this should appear:<br \/>\n<strong>listening for SMTP on [23.37.149.233]:25 [23.37.149.233]:587 [81.37.153.126]:25 [81.37.153.126]:587 [59.94.132.164]:25 [59.94.132.164:587]<\/strong><\/p>\n<p>Done. Now, Sophos UTM will intercept your incoming MX traffic (and if setup right, forward non-junk emails to your internal mail server) while the other IP address is useable for your users as an authenticated relay-server.\u00c2\u00a023.37.149.232 is used directly by the mail server,\u00c2\u00a023.37.149.233,\u00c2\u00a081.37.153.126 and\u00c2\u00a059.94.132.164 by Sophos as incoming MX server.<\/p>\n<div class=\"tweetthis\" style=\"text-align:left;\"><p> <a class=\"tt\" href=\"http:\/\/twitter.com\/share?url=https:\/\/blog.campodoro.org\/?p=2230&text=Sophos+%2F+Astaro+UTM+%E2%80%93+Limit+and+separate+SMTP+Proxy+IP+addresses+%23campodoro+%23tips+%23apple&via=goudkamp&related=richardxthripp%2Ctweetthisplugin\" title=\"Twitter\"><img decoding=\"async\" class=\"nothumb\" src=\"http:\/\/blog.campodoro.org\/wp-content\/plugins\/tweet-this\/icons\/en\/twitter\/tt-twitter.png\" alt=\"Post to Twitter\" \/><\/a> <a class=\"tt\" href=\"http:\/\/twitter.com\/share?url=https:\/\/blog.campodoro.org\/?p=2230&text=Sophos+%2F+Astaro+UTM+%E2%80%93+Limit+and+separate+SMTP+Proxy+IP+addresses+%23campodoro+%23tips+%23apple&via=goudkamp&related=richardxthripp%2Ctweetthisplugin\" title=\"Twitter\">Tweet<\/a> <a class=\"tt\" href=\"http:\/\/delicious.com\/post?url=https:\/\/blog.campodoro.org\/?p=2230&amp;title=Sophos+%2F+Astaro+UTM+%E2%80%93+Limit+and+separate+SMTP+Proxy+IP+addresses\" title=\"Post to Delicious\"><img decoding=\"async\" class=\"nothumb\" src=\"http:\/\/blog.campodoro.org\/wp-content\/plugins\/tweet-this\/icons\/en\/delicious\/tt-delicious.png\" alt=\"Post to Delicious\" \/><\/a> <a class=\"tt\" href=\"http:\/\/delicious.com\/post?url=https:\/\/blog.campodoro.org\/?p=2230&amp;title=Sophos+%2F+Astaro+UTM+%E2%80%93+Limit+and+separate+SMTP+Proxy+IP+addresses\" title=\"Post to Delicious\">Post to Delicious<\/a> <a class=\"tt\" href=\"http:\/\/www.facebook.com\/share.php?u=https:\/\/blog.campodoro.org\/?p=2230&amp;t=Sophos+%2F+Astaro+UTM+%E2%80%93+Limit+and+separate+SMTP+Proxy+IP+addresses\" title=\"Post to Facebook\"><img decoding=\"async\" class=\"nothumb\" src=\"http:\/\/blog.campodoro.org\/wp-content\/plugins\/tweet-this\/icons\/en\/facebook\/tt-facebook.png\" alt=\"Post to Facebook\" \/><\/a> <a class=\"tt\" href=\"http:\/\/www.facebook.com\/share.php?u=https:\/\/blog.campodoro.org\/?p=2230&amp;t=Sophos+%2F+Astaro+UTM+%E2%80%93+Limit+and+separate+SMTP+Proxy+IP+addresses\" title=\"Post to Facebook\">Post to Facebook<\/a><\/p><\/div>","protected":false},"excerpt":{"rendered":"<p>As a default, Sophos \/ Astaro UTM&#8217;s SMTP Proxy listens on all external IP addresses. Quite annoying if you have an internal mail server that you want to let your external users use for sending (authenticated) emails, since UTM will &hellip; <a href=\"https:\/\/blog.campodoro.org\/?p=2230\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":2236,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[176,175],"tags":[180,177,178,179,181],"class_list":["post-2230","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-exim","category-firewall","tag-astaro","tag-exim-2","tag-firewall-2","tag-sophos","tag-utm"],"_links":{"self":[{"href":"https:\/\/blog.campodoro.org\/index.php?rest_route=\/wp\/v2\/posts\/2230"}],"collection":[{"href":"https:\/\/blog.campodoro.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.campodoro.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.campodoro.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.campodoro.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2230"}],"version-history":[{"count":7,"href":"https:\/\/blog.campodoro.org\/index.php?rest_route=\/wp\/v2\/posts\/2230\/revisions"}],"predecessor-version":[{"id":2240,"href":"https:\/\/blog.campodoro.org\/index.php?rest_route=\/wp\/v2\/posts\/2230\/revisions\/2240"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.campodoro.org\/index.php?rest_route=\/wp\/v2\/media\/2236"}],"wp:attachment":[{"href":"https:\/\/blog.campodoro.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2230"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.campodoro.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2230"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.campodoro.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2230"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}