Screen OS

last person joined: 8 months ago 

This is a legacy community with limited Juniper monitoring.
  • 1.  Allow Mail through NS-50

    Posted 08-06-2009 12:31
    I have configured a NS-50 setup in transparent mode on my network and everything is working as it should be except that mail is not being delivered to my exchange server.  If I remove the firewall all the mail then gets delivered to my users accounts.  Does anyone know what this problem is or how to resolve it.  Thanks


  • 2.  RE: Allow Mail through NS-50

    Posted 08-06-2009 13:09

    Since you didn't really tell much about your environment, i am asuming the following. Please correct any wrong assumption.

     

    - You are using 2 zones, v1-trust and v1-untrust.

    - All your clients are in v1-treust

    - Your mailserver is in v1-trust

    - Internet access is working

    - Your mailserver expects mail to be delivered via SMTP on port 25

     

    What do your security policies look like ? Did you allow traffic from v1-untrust to v1-trust ? Specificly, smtp towards your mailserver ?

    Can your mailserver reach the internet ?



  • 3.  RE: Allow Mail through NS-50

    Posted 08-06-2009 14:34
    Yes I am using 2 zones, v1-trust and v1-untrust, clients and mailserver are in v1-trust, internet is working, I can send mail but cannot recieve it.  The only policy I have in place is from v1-trust to v1-untrust any any any.  I tried playing around with some of the mail policies allowing v1-untrust to v1-trust, but was unsucessful in making anything work.  From the exchange server I can access the internet.


  • 4.  RE: Allow Mail through NS-50

    Posted 08-06-2009 14:44

    You are going to need a policy to allow traffic to flow from the untrust zone to the trust zone. By default there is no policy so there is not traffic. Many different ways to handle this. You could create a MIP on your untrust interface mapping the internal IP of your Exchange server to an external IP and then create a policy from untrust to trust any to MIP.

     

    That is just one simple way - lots of solutions to this problem depending on your setup and desired traffic flow.



  • 5.  RE: Allow Mail through NS-50
    Best Answer

    Posted 08-06-2009 14:55

    Since he is running transparant mode i wouldn't see fit for a MIP.

     

    Basicly setting a policy from v1-untrust source any to v1-trust destination mailserver service smtp should do i think.

     

     

    Dennis



  • 6.  RE: Allow Mail through NS-50

    Posted 08-06-2009 15:37

    Hey Dennis - yes, I guess it would help to fully read the post......  -- I just kinda missed that whole big "transparent" word..

     

    Thanks.



  • 7.  RE: Allow Mail through NS-50

    Posted 08-07-2009 07:53
    When setting up this policy, do I need to put the IP address of the exchange server?  I ask because I setup a policy from v1-untrust to v1-trust to allow mail smtp service but that still didnt work.


  • 8.  RE: Allow Mail through NS-50

    Posted 08-07-2009 08:23

    Its not required to insert the ip address of the mailserver. You could test with source any,. destination any and service any in your policy.

     

    Once you've done that, you should be able to ping your server also (if ping is on), from the interface which is in v1-untrust.



  • 9.  RE: Allow Mail through NS-50

    Posted 08-07-2009 08:55
    Thanks Dennis, problem solved, set policy v1-untrust to v1-trust source ANY to destination IP address of exchange server service MAIL, and it worked, my users inboxes where immediately flodded with emails that had been sitting outside the firewall.  The policy ANY, ANY, ANY from untrust to trust still didnt work. 
    Message Edited by mattjames07 on 08-07-2009 08:55 AM


  • 10.  RE: Allow Mail through NS-50

    Posted 08-07-2009 09:10

    Great!

     

    For your information, v1-untrust is not the same as untrust and neither is v1-trust the same as trust.

    In transparent mode the layer2 zones (v1-xxxx) are used in stead of the layer3 zones trust/untrust.



  • 11.  RE: Allow Mail through NS-50

    Posted 08-07-2009 09:21
    The ANY, ANY, ANY, policy was set up on the v1-untrust to v1-trust and still did not allow mail traffic through.Sorry for the confusion as I did not use the proper syntax.