<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SMTP over 587 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/SMTP-over-587/m-p/59858#M12125</link>
    <description>&lt;P&gt;The drop is not happening regularly its intermittent. Among 7-10 accept packet we getting two drop packets.&lt;/P&gt;&lt;P&gt;Tried "fw up_execute" command and the IP is matching with the corresponding rule.&lt;/P&gt;&lt;P&gt;nslookup&amp;nbsp; is working from the firewall.&lt;/P&gt;</description>
    <pubDate>Thu, 08 Aug 2019 08:20:46 GMT</pubDate>
    <dc:creator>sajin</dc:creator>
    <dc:date>2019-08-08T08:20:46Z</dc:date>
    <item>
      <title>SMTP over 587</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SMTP-over-587/m-p/59811#M12104</link>
      <description>&lt;P&gt;One of our server is trying to access the domain "smtp.office365.com" with port 587. We configured Domain object and could see there are some intermittent drop in the firewall by the CLEAN UP RULE.&lt;/P&gt;&lt;P&gt;In the port 587, protocol SMTP is selected and after that we couldn't see drop but the traffic being bypassed.&lt;/P&gt;&lt;P&gt;Please explain by&amp;nbsp; adding the protocol why the traffic is being bypassed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 12:15:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SMTP-over-587/m-p/59811#M12104</guid>
      <dc:creator>sajin</dc:creator>
      <dc:date>2019-08-07T12:15:27Z</dc:date>
    </item>
    <item>
      <title>Re: SMTP over 587</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SMTP-over-587/m-p/59813#M12105</link>
      <description>&lt;P&gt;I would suggest that you should:&lt;/P&gt;
&lt;P&gt;- Explain the first configuration including defined objects, their definition and the used rule(s)&lt;/P&gt;
&lt;P&gt;- explain how you have changed what where for the second configuration&lt;/P&gt;
&lt;P&gt;-. explain the differences in behavior of both configurations and what you mean with bypassed traffic ?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 12:27:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SMTP-over-587/m-p/59813#M12105</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-08-07T12:27:43Z</dc:date>
    </item>
    <item>
      <title>Re: SMTP over 587</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SMTP-over-587/m-p/59817#M12107</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;PLz see the attachment&lt;/P&gt;&lt;P&gt;In the attachment,&amp;nbsp; server&amp;nbsp; needs to reach Domain Objects&amp;nbsp; with port 587 and there were drops in the logs.&lt;/P&gt;&lt;P&gt;As the port 587 is SMTP, we added the protocol SMTP in the corresponding port.&lt;/P&gt;&lt;P&gt;After that the traffic is bypassed in the logs its showing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the attachment you can understand whats going on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 07 Aug 2019 13:24:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SMTP-over-587/m-p/59817#M12107</guid>
      <dc:creator>sajin</dc:creator>
      <dc:date>2019-08-07T13:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: SMTP over 587</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SMTP-over-587/m-p/59821#M12110</link>
      <description>&lt;P&gt;As i do not see the drop logs i can not assume a reason for the drops - but what is meant with bypass ? I only know bypass behavior from TP, an access rule can only accept, reject or drop...&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 14:42:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SMTP-over-587/m-p/59821#M12110</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-08-07T14:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: SMTP over 587</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SMTP-over-587/m-p/59835#M12118</link>
      <description>&lt;P&gt;I think the bypass action comes from applicationcontrol. SMTP on Port 587 is Encrypted SMTP. And I think the firewall is smart enough to detect the first connection on standard port 25 and then after seeing a StartTLS command moving to port 587.But doing a bypass because the connection is encrypted and can‘t be inspected without MTA on the gateway.&lt;/P&gt;&lt;P&gt;If you could show us more from the log we can see more needed details.&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 20:09:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SMTP-over-587/m-p/59835#M12118</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-08-07T20:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: SMTP over 587</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SMTP-over-587/m-p/59850#M12120</link>
      <description>&lt;P&gt;The&amp;nbsp; drop is happening in the Final Clean UP RULE and in "fw ctl zdebug drop"it show only the clean up rule block.&lt;/P&gt;&lt;P&gt;Removing the Domain Object&amp;nbsp; in the rule and when giving the resolvable IP in the destination there is no drop.&lt;/P&gt;&lt;P&gt;So is something happening with the the Domain Object or the port 587.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2019 07:04:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SMTP-over-587/m-p/59850#M12120</guid>
      <dc:creator>sajin</dc:creator>
      <dc:date>2019-08-08T07:04:59Z</dc:date>
    </item>
    <item>
      <title>Re: SMTP over 587</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SMTP-over-587/m-p/59852#M12122</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/29074"&gt;@sajin&lt;/a&gt;&amp;nbsp;Much more likely, your domain object cannot be resolved on your FW. Did you check if it is there?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2019 07:49:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SMTP-over-587/m-p/59852#M12122</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-08-08T07:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: SMTP over 587</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SMTP-over-587/m-p/59858#M12125</link>
      <description>&lt;P&gt;The drop is not happening regularly its intermittent. Among 7-10 accept packet we getting two drop packets.&lt;/P&gt;&lt;P&gt;Tried "fw up_execute" command and the IP is matching with the corresponding rule.&lt;/P&gt;&lt;P&gt;nslookup&amp;nbsp; is working from the firewall.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2019 08:20:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SMTP-over-587/m-p/59858#M12125</guid>
      <dc:creator>sajin</dc:creator>
      <dc:date>2019-08-08T08:20:46Z</dc:date>
    </item>
    <item>
      <title>Re: SMTP over 587</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SMTP-over-587/m-p/60073#M12162</link>
      <description>The drops with Domain Objects points to intermittent DNS lookup failures, as we do look it up periodically.&lt;BR /&gt;Recommend opening up a TAC case.&lt;BR /&gt;</description>
      <pubDate>Mon, 12 Aug 2019 01:11:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SMTP-over-587/m-p/60073#M12162</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-08-12T01:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: SMTP over 587</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SMTP-over-587/m-p/202230#M33669</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have a similar issue, does anyone has a solution handy.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 15:50:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SMTP-over-587/m-p/202230#M33669</guid>
      <dc:creator>yemiokubule</dc:creator>
      <dc:date>2024-01-04T15:50:37Z</dc:date>
    </item>
  </channel>
</rss>

