Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > Mail Security: SMTP, POP3, Antispam and Antivirus

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #11 (permalink)  
Old 06-18-2009, 08:05 PM
Junior Member
 
Join Date: Sep 2004
Location: Budapest, Hungary
Posts: 9
Default

Oh, I thought I had read in your first post that you turned off the port forward to the barracuda.

This is the easiest way to set up the inbound mail:
- disable the NAT
- make the mx record point to the public IP of the Astaro
- add your mail domain(s) to Domains on the Routing tab
- set "Route by" to "Static Host list"
- add an object with the private address of the barracuda to the "Host list"
- for a start, turn "Verify recipients" off
- and, very important: tell your barracuda to accept mail from the internal interface of the ASG

For inbound mail, this is all you need. If this does not work, I would strongly suspect that the configuration problem is on the barracuda (i.e. it does not accept mail relayed through the Astaro).

For outbound mail, you can either send directly, or if you relay through the proxy on your ASG, then you need to add your internal network (or only the IPs allowed to send mail) to the "Host-based relay" on the Relaying tab. But inbound and outbound mail don't actually have much to do with each other.

This is, of course, a very simplistic guide. If it does not get you through, please find the relevant lines in the smtp log and post them here.

Good luck!
Reply With Quote
  #12 (permalink)  
Old 06-18-2009, 08:07 PM
Junior Member
 
Join Date: Sep 2004
Location: Budapest, Hungary
Posts: 9
Default

Quote:
Originally Posted by Asok View Post
If this does not work, I would strongly suspect that the configuration problem is on the barracuda (i.e. it does not accept mail relayed through the Astaro).
For example, check that the barracuda does not use RBL's when it gets the mail from the ASG. You should have a look in the barracuda logs for anything suspicious.
Reply With Quote
  #13 (permalink)  
Old 06-18-2009, 08:20 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 5,391
Default

Yes, on the 'Relaying' tab, add your Exchange server to 'Allowed hosts'. The rest of the tab likely should be left empty, but with 'Scan relayed (outgoing) messages' checked to enable Anti-Virus scanning of sent mail.

My guess is that the Barracuda doesn't know how to answer when you set 'Verify Recipients' to "With callout." Depending on your network topology, it might also be blocking your AD requests. Have you confirmed that AD authentication works correctly?

It's unclear to me why you would want to keep the Barracuda if you have an Astaro Mail Security subscription. The current Astaro Anti-Spam is about as close to 100% right as possible, and with the upcoming V7.5, the CommTouch IP Reputation check should eliminate over 90% of the little bit that gets through today.

Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #14 (permalink)  
Old 06-18-2009, 08:27 PM
Junior Member
 
Join Date: Sep 2004
Location: Budapest, Hungary
Posts: 9
Default

Quote:
Originally Posted by BAlfson View Post
My guess is that the Barracuda doesn't know how to answer when you set 'Verify Recipients' to "With callout."
Yep, that's why I asked him (her) to turn verify recipients off in one of my first tips. But it did not seem to help...
Reply With Quote
  #15 (permalink)  
Old 06-18-2009, 09:03 PM
Junior Member
 
Join Date: Mar 2006
Posts: 12
Default Update

Working now, but I changed a couple of things...probably better this way anyway.

I left the Nat translation of port 25 going to my barracuda then I after the barracuda processes it I forward it on to the Astaro appliance for processing, then on to my exchange server. I'm sure it's better to let the barracuda do most of the processing before it gets to my firewall to save on the firewall resources.

I disabled the transparent mode as well and listed ed only my exchange server and barracuda in the allowed hosts to relay box.

So far the astar hasn't blcoked anything that my barracuda hasn't so if it continues like that I may just shut down the smtp proxy anyway.


Thanks for the help.
Reply With Quote
  #16 (permalink)  
Old 06-18-2009, 10:21 PM
Junior Member
 
Join Date: Sep 2004
Location: Budapest, Hungary
Posts: 9
Default

Quote:
Originally Posted by jslaton View Post
I left the Nat translation of port 25 going to my barracuda then I after the barracuda processes it I forward it on to the Astaro appliance for processing, then on to my exchange server.
This makes it almost certain that the problem was with the barracuda configuration (for some reason it did not accept the mails coming from the Astaro).

Quote:
Originally Posted by jslaton View Post
So far the astar hasn't blcoked anything that my barracuda hasn't so if it continues like that I may just shut down the smtp proxy anyway.
Or you can do it the other way around, and save money on the barracuda. (I am not an Astaro employee... ) Of course, it depends on your mail load.

I'm glad you succeeded finally.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 02:57 AM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.