- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Is there a reason why a mail security appliance that's located at the DMZ cannot send mail to outside of my organization? Port 25 is enabled on the firewall. SmartView tracker does not show dropped smtp traffic from the host. Even a simple telnet from the appliance on port 25 is dropped.
Any suggestion would greatly be appreciated.
Thanks
It does not look like the traffic is leaving the firewall. All I see on the tcpdump is TCP Retransmission error to the destination SMTP server.
Ex.
6 30.999253 21.168.1.101 173.194.204.26 TCP 74 [TCP Retransmission] 34749 → 25 [SYN] Seq=0 Win=14600 Len=0 MSS=1460 SACK_PERM=1 TSval=1483731605 TSecr=0 WS=4
What about the access policy rule for DMZ with service SMTP ?
Check SmartLog for Anti-Bot blade entries calling out possibly malicious e-mail or SPAM from your DMZ appliance.
The situation sounds somewhat similar to another community discussion we are having: "Having issues with firewall dropping mail as spam" https://community.checkpoint.com/t5/IPS-Anti-Virus-Anti-Bot-Anti/Having-issues-with-firewall-droppin...
How about this issue ? I met the SMTP issue after upgrade R80.10 from R75.47.
This issue cased a lot of email have been delayed, even some emails can’t be received. It affects customer’s business seriously.
I tried to capture packet form new appliance, no found abnormal SMTP traffic. After rollback to old checkpoint appliance, the SMTP traffic is normal.
New appliance only enable firewall blade.
I have uploaded capture traffic, the traffic is not normal in red.
I have the policy that any to mail serve ip address service any policy. See attached screenshot.
Mail server ip: 202.38.134.236 , Tcpdump found lot of retransmission, attached screenshot.
And I tried to fw ctl zdebug + drop | grep 202.38.134.236 ,but no found.
Do we have any specific setting relevant SMTP on R80.X verion and above ?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 21 | |
| 18 | |
| 7 | |
| 6 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY