Ask Experts Questions for FREE Help !
Ask
    EyeNoNothing's Avatar
    EyeNoNothing Posts: 35, Reputation: 3
    Junior Member
     
    #1

    May 12, 2010, 10:21 AM
    Sonicwall Port 25 exception
    I'm hoping someone can help me out here. Our company has a new Sonicwall Firewall installed. We recently became blacklisted due to a virus/trojan and some SPAM. I believe I need to block all outgoing traffic on Port 25 except that of our mail server but I'm not entirely sure how to go about it.

    I did not originally set up the firewall, but I do have admin access and some history with watchguard configs.
    raj2160's Avatar
    raj2160 Posts: 29, Reputation: 1
    New Member
     
    #2

    May 20, 2010, 02:57 PM

    This is actually easier than you think and is done for all companies I've worked for

    You just need to create the acl with allow entries before deny entries

    So allow mail host any port 25
    Deny any any port 25

    Depending on where you put the entry ingress (in) port or egress (out) port you'll need to pay attention to the internal or natted ip of the mail server and of course you don't want to have this as an incoming entry from your internet port because then you'll block all mail traffic coming into your domain.

    Best to put the acl on your egress (internet) port with direction out to minimize cpu utilization
    EyeNoNothing's Avatar
    EyeNoNothing Posts: 35, Reputation: 3
    Junior Member
     
    #3

    May 21, 2010, 05:54 AM
    Thanks raj! I set it up to block all outgoing to port 25 then created one to allow the IP of the mail server and listed it as a higher priority than the deny all. We can still send mail so it appears to be working!

Not your question? Ask your question View similar questions

 

Question Tools Search this Question
Search this Question:

Advanced Search

Add your answer here.


Check out some similar questions!

Exception [ 1 Answers ]

Try block is possible inside the catch block in java

The exception unknown software exception (0xc0000409) occurred in the application at [ 2 Answers ]

the exception unknown software exception (0xc0000409) occurred in the application at location 0x5b86a3c0

Replace data/fax port with firewire port [ 2 Answers ]

I want to buy a dell inspiron 531 computer from costco. It has a TV tuner and a 56K PCI Data/Fax Modem. I know the TV tuner uses one of the two available pci slots, but does a data/fax modem use anothwer pci slot? I want to have an open pci slot so I can add a firewire port. If the data/fax uses a...


View more questions Search