- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Register HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Dear CheckMates,
I am in the process of trying to replace a SOPHOS UTM with a Check Point 6400 appliance cluster.
Currently the SOPHOS is acting as an SMTP proxy/relay and the customer would like to have the Check Point take over this functionality.
I have so far not been able to clearly identify how to achieve this.
There is no mail server on the internal side that we can use. For the outgoing SMTP traffic the idea is to NAT the traffic to a dedicated IP address for the purposes of DMARC and other authorisation based on the SMTP IP address.
I was looking into the MTA option in the config but this is clearly more oriented towards acting as a man-in-the-middle between the external MTA and the Internal Mail Server.
Any suggestions would be greatly appreciated.
Best regards,
Andrew
Our MTA is provided in the context of our Threat Prevention/DLP Features and uses Postfix.
You can edit the configuration as appropriate to support such a configuration: https://support.checkpoint.com/results/sk/sk101870
Whether this configuration would be formally supported is a separate question.
you don't have to change much, there is not one internal exchange server but many server using SMTP with an "open" MTA (use custom interfaces, not all external) and the forwarding Mail server is external.
It should work.
ATRG: Mail Transfer Agent (MTA) (checkpoint.com)
The MTA is part of the Content Awareness
Regards
Peter
And in the Current Documentation:
Configuring the Security Gateway as a Mail Transfer Agent (checkpoint.com)
Hello Andrew,
the question is how do the Clients communicate with there Mailbox servers? And how do they send E-Mails. O365 uses https not smtp. Were are the Mailbox Servers?
Can you post a topology overview?
Regards
Peter
The devices in the internal VLANs do not use a mail server because they use outgoing SMTP only (e.g. Scan to email device), in the past they had the SOPHOS as their mail server and it acted as a Proxy/Relay and handled the smtp traffic directly off the devices. When the message was being transferred to the outside world it would have a dedicated NAT IP address associated with all outgoing SMTP traffic so that the upstream mail servers would recognise it in their DMARC verification and if they used any IP based filtering for inbound smtp.
Our MTA is provided in the context of our Threat Prevention/DLP Features and uses Postfix.
You can edit the configuration as appropriate to support such a configuration: https://support.checkpoint.com/results/sk/sk101870
Whether this configuration would be formally supported is a separate question.
you don't have to change much, there is not one internal exchange server but many server using SMTP with an "open" MTA (use custom interfaces, not all external) and the forwarding Mail server is external.
It should work.
Thanks guys for your suggestions and help/support.
In the end the customer did not want to take any chances with the solution being not supported so I persuaded them to re-architect their solution and use an internal mail relay server which conformed to their internal security guidelines.
Again much appreciated.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealTue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY