Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Andrew-OCD
Contributor

Configuring Check Point Gateway to act as SMTP proxy/relay

Dear CheckMates,

I am in the process of trying to replace a SOPHOS UTM with a Check Point 6400 appliance cluster.

Currently the SOPHOS is acting as an SMTP proxy/relay and the customer would like to have the Check Point take over this functionality.

I have so far not been able to clearly identify how to achieve this.

There is no mail server on the internal side that we can use. For the outgoing SMTP traffic the idea is to NAT the traffic to a dedicated IP address for the purposes of DMARC and other authorisation based on the SMTP IP address.

I was looking into the MTA option in the config but this is clearly more oriented towards acting as a man-in-the-middle between the external MTA and the Internal Mail Server.

Any suggestions would be greatly appreciated.

Best regards,

Andrew

 

0 Kudos
6 Replies
JP_Rex
Contributor
Contributor

ATRG: Mail Transfer Agent (MTA) (checkpoint.com)

 

The MTA is part of the Content Awareness 

Regards

Peter

0 Kudos
JP_Rex
Contributor
Contributor

0 Kudos
JP_Rex
Contributor
Contributor

Hello Andrew,

the question is how do the Clients communicate with there Mailbox servers? And how do they send E-Mails. O365 uses https not smtp. Were are the Mailbox Servers?

Can you post a topology overview?

 

Regards

 

Peter

0 Kudos
Andrew-OCD
Contributor

The devices in the internal VLANs do not use a mail server because they use outgoing SMTP only (e.g. Scan to email device), in the past they had the SOPHOS as their mail server and it acted as a Proxy/Relay and handled the smtp traffic directly off the devices. When the message was being transferred to the outside world it would have a dedicated NAT IP address associated with all outgoing SMTP traffic so that the upstream mail servers would recognise it in their DMARC verification and if they used any IP based filtering for inbound smtp.

0 Kudos
PhoneBoy
Admin
Admin

Our MTA is provided in the context of our Threat Prevention/DLP Features and uses Postfix.
You can edit the configuration as appropriate to support such a configuration: https://support.checkpoint.com/results/sk/sk101870 
Whether this configuration would be formally supported is a separate question.

0 Kudos
JP_Rex
Contributor
Contributor

you don't have to change much, there is not one internal exchange server but many server using SMTP with an "open" MTA (use custom interfaces, not all external) and the forwarding Mail server is external.

It should work.

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events