<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem configuring rules for our mail server using anti spam cloud service in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/problem-configuring-rules-for-our-mail-server-using-anti-spam/m-p/204711#M60189</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/81168"&gt;@MichelD&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I would recommend that when you are trying to get this to work, you override the interzone-default policy to enable 'logging-start' so that you can see any traffic that is getting dropped due to your security policy configuration. This will allow you to then build out the security policies as needed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both of the security policies that you have displayed are showing hits, and your NAT policies are indicating that they are getting used as well. With the interzone-default logging enabled, you should be able to view the traffic logs and see where exactly things are breaking down.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 11 Mar 2018 01:45:55 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-03-11T01:45:55Z</dc:date>
    <item>
      <title>Problem configuring rules for our mail server using anti spam cloud service</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-configuring-rules-for-our-mail-server-using-anti-spam/m-p/204501#M60143</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I think I&amp;lt;m not on the right track and search documentation to help. i tried to replicate the logic from my olf checkpoint fw. I guess it is not a good idea.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please HELP!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My configuration is the following (no real IP addresses)&lt;/P&gt;&lt;P&gt;Mail Private Server in a trusted zone (Servers-Zone) PRV-MAIL-SERVER 10.10.5..3 on Interface1/3&lt;/P&gt;&lt;P&gt;The Public Address PUB-MAIL-SERVER 70.34.125.2 (1 of 5 addresses on Interface1/1)&lt;/P&gt;&lt;P&gt;The anti-spam cloud service ANTISPAM-ADDR_GROUP (3 IP addresses range on port 25)&lt;/P&gt;&lt;P&gt;The WebMail Public Addrees WEBMAIL 70.34.125.2 (same as the mail server but port 443) on Interface1/2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the following NAT rule for outgoing mails&lt;/P&gt;&lt;P&gt;src-zone : Servers-Zone&amp;nbsp;&lt;/P&gt;&lt;P&gt;dst-zone : Internet-Zone&amp;nbsp;&lt;/P&gt;&lt;P&gt;dst-interface : Internet1/1&lt;/P&gt;&lt;P&gt;src-addr : PRV-MAIL-SERVER&lt;/P&gt;&lt;P&gt;dest-addr : any&lt;/P&gt;&lt;P&gt;Service : smtp&lt;/P&gt;&lt;P&gt;Src-translation: static-ip: PUB-MAIL-SERVER, bidirectional : yes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and the following NAT rule for then incoming mails&lt;/P&gt;&lt;P&gt;src-zone : Internet-Zone&amp;nbsp;&lt;/P&gt;&lt;P&gt;dst-zone : Servers-Zone&amp;nbsp;&lt;/P&gt;&lt;P&gt;dst-interface : Internet1/3&lt;/P&gt;&lt;P&gt;src-addr : PUB-MAIL-SERVER&lt;/P&gt;&lt;P&gt;dest-addr : any&lt;/P&gt;&lt;P&gt;Service : smtp&lt;/P&gt;&lt;P&gt;Src-translation: static-ip: PRV-MAIL-SERVER, bidirectional : yes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Security Rules are (Outgoing email):&lt;/P&gt;&lt;P&gt;src Zone : Servers-Zone&lt;/P&gt;&lt;P&gt;src Address : PRV-MAIL-SERVER&lt;/P&gt;&lt;P&gt;dst Zone : Internet-Zone&lt;/P&gt;&lt;P&gt;dst-Addr :&amp;nbsp;&lt;SPAN&gt;ANTISPAM-ADDR_GROUP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;application : smtp and Service : application-default&lt;/P&gt;&lt;P&gt;Action : Allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Security Rules are (Incoming email):&lt;/P&gt;&lt;P&gt;src Zone : Internet-Zone&lt;/P&gt;&lt;P&gt;src Address : &lt;SPAN&gt;ANTISPAM-ADDR_GROUP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;dst Zone : Source-Zone&lt;/P&gt;&lt;P&gt;dst-Addr :&amp;nbsp;&lt;SPAN&gt;PRV-MAIL-SERVER&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;application : smtp and Service : application-default&lt;/P&gt;&lt;P&gt;Action : Allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can send email from the mail server to gmail and the action is successful and logged&lt;/P&gt;&lt;P&gt;The reply is not working and nothing in the logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Michel&lt;/P&gt;</description>
      <pubDate>Fri, 09 Mar 2018 03:14:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-configuring-rules-for-our-mail-server-using-anti-spam/m-p/204501#M60143</guid>
      <dc:creator>MichelD</dc:creator>
      <dc:date>2018-03-09T03:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: Problem configuring rules for our mail server using anti spam cloud service</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-configuring-rules-for-our-mail-server-using-anti-spam/m-p/204524#M60149</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/81168"&gt;@MichelD&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would deactivate the 'bidirectional' option on your first NAT rule since you're building NAT policy in both directions (you can either do bidirectional, or do 2 policies, 1 for each direction... I recommend doing the 2 policy method as this is more readable and less prone to mistakes)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;your second policy needs to be internet-zone to internet-zone, this is because the original packet's zones are determined by a route lookup: the source is located on the internet (0.0.0.0/0) and the original destination is also on the internet (external interface ip)&lt;/P&gt;
&lt;P&gt;your destination also needs to be the IP PUB-MAIL-SERVER, not any, the source should probably be the ANTISPAM-ADDR-GROUP (so you only allow inbound NAT from those addresses)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;your outbound security policy is fine, but for the inbound security policy the destination IP also needs to be PUB-MAIL-SERVER, instead of the private one&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here's a little article + video about NAT which may be helpful : &lt;A href="https://live.paloaltonetworks.com/t5/Tutorials/Getting-Started-Network-Address-Translation-NAT/ta-p/116340" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Tutorials/Getting-Started-Network-Address-Translation-NAT/ta-p/116340&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Mar 2018 09:09:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-configuring-rules-for-our-mail-server-using-anti-spam/m-p/204524#M60149</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-03-09T09:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: Problem configuring rules for our mail server using anti spam cloud service</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-configuring-rules-for-our-mail-server-using-anti-spam/m-p/204699#M60185</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14192i7DCD9C9A1407D597/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="NAT.jpg" alt="NAT.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SECURITY.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14193i0B3F192F35835426/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="SECURITY.jpg" alt="SECURITY.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I changed the configuration as your recommendations. I also read the article. Since I changed the values. the behaviour is &amp;nbsp;a little bit different, but cannot receive emails. The Send is working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the Log/Traffic does not show any information about what's going wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I checked all the adresses with the values in our firewall we are replacing. &amp;nbsp;I also tried different scenarios based on what you explain.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Michel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 10 Mar 2018 21:17:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-configuring-rules-for-our-mail-server-using-anti-spam/m-p/204699#M60185</guid>
      <dc:creator>MichelD</dc:creator>
      <dc:date>2018-03-10T21:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: Problem configuring rules for our mail server using anti spam cloud service</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-configuring-rules-for-our-mail-server-using-anti-spam/m-p/204711#M60189</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/81168"&gt;@MichelD&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I would recommend that when you are trying to get this to work, you override the interzone-default policy to enable 'logging-start' so that you can see any traffic that is getting dropped due to your security policy configuration. This will allow you to then build out the security policies as needed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both of the security policies that you have displayed are showing hits, and your NAT policies are indicating that they are getting used as well. With the interzone-default logging enabled, you should be able to view the traffic logs and see where exactly things are breaking down.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Mar 2018 01:45:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-configuring-rules-for-our-mail-server-using-anti-spam/m-p/204711#M60189</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-03-11T01:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: Problem configuring rules for our mail server using anti spam cloud service</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-configuring-rules-for-our-mail-server-using-anti-spam/m-p/204731#M60193</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;wrote:&lt;BR /&gt;&lt;P&gt;Both of the security policies that you have displayed are showing hits,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This brings up a good point...Embedded rule usage is a feature set of PAN-OS 8.1.X.&amp;nbsp; I'm not trying to jump and say merely the code base is the issue, but for the sake of stability to a production environment&amp;nbsp;running an established / stable code release would also be a good idea?&lt;/P&gt;</description>
      <pubDate>Sun, 11 Mar 2018 15:08:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-configuring-rules-for-our-mail-server-using-anti-spam/m-p/204731#M60193</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2018-03-11T15:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: Problem configuring rules for our mail server using anti spam cloud service</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-configuring-rules-for-our-mail-server-using-anti-spam/m-p/204732#M60194</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/81168"&gt;@MichelD&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&amp;nbsp;brings up a rather good point, and one that I kind of didn't think about. While 8.1.0 is released I would hesitate to use it in a production enviroment where you are actually publishing services. So far, I've only deployed 8.1.0 on LAB equipment, and the PA-220s that I utilize for our IT department to make a tunnel back to our main office from their houses.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not going to go as far as to say that 8.1.0 is your issue here, because I don't actually believe it is, but I wouldn't be running 8.1.0 in this capacity just yet.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just want to stress here though, I don't think 8.1.0 is your actual issue. I think if you do as I stated you'll see something that you aren't allowing in your security policies that is getting denied by the interzone-default policy.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Mar 2018 15:13:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-configuring-rules-for-our-mail-server-using-anti-spam/m-p/204732#M60194</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-03-11T15:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: Problem configuring rules for our mail server using anti spam cloud service</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-configuring-rules-for-our-mail-server-using-anti-spam/m-p/204770#M60208</link>
      <description>&lt;P&gt;Thank you everybody for your input.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My problem is now solve. In my case, 8.1 was not the culprit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are my final configuration and working great going through the anti-spam cloud service in both directions.&lt;/P&gt;&lt;P&gt;Line with the (MODIFIED) are the corrections to my original configuration.&amp;nbsp;&lt;/P&gt;&lt;P&gt;To find out what was wrong, I had created an any-to-any temporary (5 minutes max) rule with the risk (i know). So I got the information in the trafic log. Logging is not enabled in the default 2 security rules.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a documentation, my physical configuration is like that:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My MX records points to the ANTISPAM-CLOUD service.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;INBOUND EMAILS ---&amp;gt; ANTISPAM-CLOUD ---&amp;gt; FW ---&amp;gt; MAIL-SERVER (Trueted Zone(&lt;/P&gt;&lt;P&gt;MAIL-SERVER (Trusted Zone) ---&amp;gt; FW ---&amp;gt; ANTISPAM-CLOUD ---&amp;gt; OUTBOUD EMAILS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the following NAT rule for outgoing mails.&lt;/P&gt;&lt;P&gt;src-zone : Servers-Zone&lt;BR /&gt;dst-zone : Internet-Zone&lt;BR /&gt;dst-interface : Internet1/1&lt;BR /&gt;src-addr : PRV-MAIL-SERVER&lt;BR /&gt;dest-addr : outbound-mail-to antispam solution (MODIFIED)&lt;BR /&gt;Service : any (MODIFIED)&lt;BR /&gt;Src-translation: static-ip: PUB-MAIL-SERVER, bidirectional : no (Bidirectional=NO)&lt;BR /&gt;&lt;BR /&gt;and the following NAT rule for then incoming mails&lt;BR /&gt;src-zone : Internet-Zone&lt;BR /&gt;dst-zone : Internet-Zone (MODIFIED)&lt;BR /&gt;dst-interface : Internet1/1 (MODIFIED)&lt;BR /&gt;src-addr : ANTISPAM-ADDR-GROUP (MODIFIED)&lt;BR /&gt;dest-addr : PUB-Mail-Server (MODIFIED)&lt;BR /&gt;Service : any (MODIFIED)&lt;BR /&gt;Src-translation: static-ip: PRV-MAIL-SERVER, bidirectional : no (Bidirectoional=NO)&lt;BR /&gt;&lt;BR /&gt;The Security Rules are (Outgoing email):&lt;BR /&gt;src Zone : Servers-Zone&lt;BR /&gt;src Address : PRV-MAIL-SERVER&lt;BR /&gt;dst Zone : Internet-Zone&lt;BR /&gt;dst-Addr : outbound-mail-to antispam solution (MODIFIED to go through the ANTISPAM)&lt;BR /&gt;application : smtp and Service : application-default&lt;BR /&gt;Action : Allow&lt;BR /&gt;&lt;BR /&gt;The Security Rules are (Incoming email):&lt;BR /&gt;src Zone : Internet-Zone&lt;BR /&gt;src Address : ANTISPAM-ADDR_GROUP&lt;BR /&gt;dst Zone : Server-Zone&lt;BR /&gt;dst-Addr : PUB-MAIL-SERVER (MODIFIED)&lt;BR /&gt;application : smtp and Service : application-default&lt;BR /&gt;Action : Allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you again,&lt;/P&gt;&lt;P&gt;Michel&lt;/P&gt;</description>
      <pubDate>Sun, 11 Mar 2018 21:54:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-configuring-rules-for-our-mail-server-using-anti-spam/m-p/204770#M60208</guid>
      <dc:creator>MichelD</dc:creator>
      <dc:date>2018-03-11T21:54:29Z</dc:date>
    </item>
  </channel>
</rss>

