<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configuring Check Point Gateway to act as SMTP proxy/relay in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-Check-Point-Gateway-to-act-as-SMTP-proxy-relay/m-p/212691#M40413</link>
    <description>&lt;P&gt;Hello Andrew,&lt;/P&gt;&lt;P&gt;the question is how do the Clients communicate with there Mailbox servers? And how do they send E-Mails. O365 uses https not smtp. Were are the Mailbox Servers?&lt;BR /&gt;&lt;BR /&gt;Can you post a topology overview?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;</description>
    <pubDate>Tue, 30 Apr 2024 11:29:48 GMT</pubDate>
    <dc:creator>JP_Rex</dc:creator>
    <dc:date>2024-04-30T11:29:48Z</dc:date>
    <item>
      <title>Configuring Check Point Gateway to act as SMTP proxy/relay</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-Check-Point-Gateway-to-act-as-SMTP-proxy-relay/m-p/212684#M40408</link>
      <description>&lt;P&gt;Dear CheckMates,&lt;/P&gt;&lt;P&gt;I am in the process of trying to replace a SOPHOS UTM with a Check Point 6400 appliance cluster.&lt;/P&gt;&lt;P&gt;Currently the SOPHOS is acting as an SMTP proxy/relay and the customer would like to have the Check Point take over this functionality.&lt;/P&gt;&lt;P&gt;I have so far not been able to clearly identify how to achieve this.&lt;/P&gt;&lt;P&gt;There is no mail server on the internal side that we can use. For the outgoing SMTP traffic the idea is to NAT the traffic to a dedicated IP address for the purposes of DMARC and other authorisation based on the SMTP IP address.&lt;/P&gt;&lt;P&gt;I was looking into the MTA option in the config but this is clearly more oriented towards acting as a man-in-the-middle between the external MTA and the Internal Mail Server.&lt;/P&gt;&lt;P&gt;Any suggestions would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 09:40:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-Check-Point-Gateway-to-act-as-SMTP-proxy-relay/m-p/212684#M40408</guid>
      <dc:creator>Andrew-OCD</dc:creator>
      <dc:date>2024-04-30T09:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Check Point Gateway to act as SMTP proxy/relay</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-Check-Point-Gateway-to-act-as-SMTP-proxy-relay/m-p/212687#M40410</link>
      <description>&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk109699" target="_blank"&gt;ATRG: Mail Transfer Agent (MTA) (checkpoint.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The MTA is part of the Content Awareness&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 11:08:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-Check-Point-Gateway-to-act-as-SMTP-proxy-relay/m-p/212687#M40410</guid>
      <dc:creator>JP_Rex</dc:creator>
      <dc:date>2024-04-30T11:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Check Point Gateway to act as SMTP proxy/relay</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-Check-Point-Gateway-to-act-as-SMTP-proxy-relay/m-p/212690#M40412</link>
      <description>&lt;P&gt;And in the Current Documentation:&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ThreatPrevention_AdminGuide/Content/Topics-TPG/Mail_Transfer_Agent.htm?Highlight=mta" target="_blank"&gt;Configuring the Security Gateway as a Mail Transfer Agent (checkpoint.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 11:17:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-Check-Point-Gateway-to-act-as-SMTP-proxy-relay/m-p/212690#M40412</guid>
      <dc:creator>JP_Rex</dc:creator>
      <dc:date>2024-04-30T11:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Check Point Gateway to act as SMTP proxy/relay</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-Check-Point-Gateway-to-act-as-SMTP-proxy-relay/m-p/212691#M40413</link>
      <description>&lt;P&gt;Hello Andrew,&lt;/P&gt;&lt;P&gt;the question is how do the Clients communicate with there Mailbox servers? And how do they send E-Mails. O365 uses https not smtp. Were are the Mailbox Servers?&lt;BR /&gt;&lt;BR /&gt;Can you post a topology overview?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 11:29:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-Check-Point-Gateway-to-act-as-SMTP-proxy-relay/m-p/212691#M40413</guid>
      <dc:creator>JP_Rex</dc:creator>
      <dc:date>2024-04-30T11:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Check Point Gateway to act as SMTP proxy/relay</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-Check-Point-Gateway-to-act-as-SMTP-proxy-relay/m-p/212851#M40457</link>
      <description>&lt;P&gt;The devices in the internal VLANs do not use a mail server because they use outgoing SMTP only (e.g. Scan to email device), in the past they had the SOPHOS as their mail server and it acted as a Proxy/Relay and handled the smtp traffic directly off the devices. When the message was being transferred to the outside world it would have a dedicated NAT IP address associated with all outgoing SMTP traffic so that the upstream mail servers would recognise it in their DMARC verification and if they used any IP based filtering for inbound smtp.&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2024 15:13:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-Check-Point-Gateway-to-act-as-SMTP-proxy-relay/m-p/212851#M40457</guid>
      <dc:creator>Andrew-OCD</dc:creator>
      <dc:date>2024-05-01T15:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Check Point Gateway to act as SMTP proxy/relay</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-Check-Point-Gateway-to-act-as-SMTP-proxy-relay/m-p/212853#M40459</link>
      <description>&lt;P&gt;Our MTA is provided in the context of our Threat Prevention/DLP Features and uses Postfix.&lt;BR /&gt;You can edit the configuration as appropriate to support such a configuration:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk101870" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk101870&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;Whether this configuration would be formally supported is a separate question.&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2024 15:41:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-Check-Point-Gateway-to-act-as-SMTP-proxy-relay/m-p/212853#M40459</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-01T15:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Check Point Gateway to act as SMTP proxy/relay</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-Check-Point-Gateway-to-act-as-SMTP-proxy-relay/m-p/212907#M40470</link>
      <description>&lt;P&gt;you don't have to change much, there is not one internal exchange server but many server using SMTP with an "open" MTA (use custom interfaces, not all external) and the forwarding Mail server is external.&lt;/P&gt;&lt;P&gt;It should work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 09:20:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-Check-Point-Gateway-to-act-as-SMTP-proxy-relay/m-p/212907#M40470</guid>
      <dc:creator>JP_Rex</dc:creator>
      <dc:date>2024-05-02T09:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Check Point Gateway to act as SMTP proxy/relay</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-Check-Point-Gateway-to-act-as-SMTP-proxy-relay/m-p/222553#M42654</link>
      <description>&lt;P&gt;Thanks guys for your suggestions and help/support.&lt;/P&gt;&lt;P&gt;In the end the customer did not want to take any chances with the solution being not supported so I persuaded them to re-architect their solution and use an internal mail relay server which conformed to their internal security guidelines.&lt;/P&gt;&lt;P&gt;Again much appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2024 09:17:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-Check-Point-Gateway-to-act-as-SMTP-proxy-relay/m-p/222553#M42654</guid>
      <dc:creator>Andrew-OCD</dc:creator>
      <dc:date>2024-08-02T09:17:37Z</dc:date>
    </item>
  </channel>
</rss>

