<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Possible Reason Why Palo Rejecting SMTP traffic containing attachments. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/possible-reason-why-palo-rejecting-smtp-traffic-containing/m-p/342591#M85851</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was . Over the past couple of days we have seen a increase in delayed or non delivered emails that contain attachments greater that approx. 3mb that are being rejected or non delivered to the mailbox transport server. It is now a permanent issue and we have identified that the firewall is the cause of the issue but I am unsure how to fix this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Steps to recreate:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Emails sent from external domain to internal domain is received by our email security platform and then forwarded to our on-premise mail server.&lt;/LI&gt;&lt;LI&gt;When the email is forwarded our email server then delivers the mail to the recipients mailbox and this is confirmed as successful.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Issues:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;A email with an attachment greater than approx. 3mb is hitting our email security platform and then queued for delivery.&lt;/LI&gt;&lt;LI&gt;When the attempt for delivery is made from the email gateway service, we get the following error repeatedly until the retry attempts expire. - &lt;STRONG&gt;Response 451 4.4.2 [internal] connection closed by remote host.&lt;/STRONG&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2020-08-06 05:32:57 PM&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Response: 451 4.4.2 [internal] connection closed by remote host&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2020-08-06 05:33:46 PM&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Delivery attempt #2&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2020-08-06 05:33:46 PM&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Recipient server:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What has been attempted:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;We have spoken with Microsoft Support and they have advised that once an email reaches the exchange transport service it is immediately passed to the recipient mailbox. Meaning no issues with configuration of transport rules and internal network.&lt;/LI&gt;&lt;LI&gt;It has been identified that these retry attempts of emails that have attachments never reach the exchange server.&lt;/LI&gt;&lt;LI&gt;The rejection error of 451 4.4.2 indicates that there is a network error between the security platform and the on premise exchange server that indicates the firewall as the cause.&lt;/LI&gt;&lt;LI&gt;Tried modifying the security policy by removing the IPS security profile and removing the service and application defaults of SMTP to be any/any with no success.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Help Required:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Really need some assistance troubleshooting the traffic coming inbound and why it is being rejected by the firewall when the email contains attachment &amp;lt;3mb.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Chris.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 06 Aug 2020 22:30:01 GMT</pubDate>
    <dc:creator>ccarter</dc:creator>
    <dc:date>2020-08-06T22:30:01Z</dc:date>
    <item>
      <title>Possible Reason Why Palo Rejecting SMTP traffic containing attachments.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-reason-why-palo-rejecting-smtp-traffic-containing/m-p/342591#M85851</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was . Over the past couple of days we have seen a increase in delayed or non delivered emails that contain attachments greater that approx. 3mb that are being rejected or non delivered to the mailbox transport server. It is now a permanent issue and we have identified that the firewall is the cause of the issue but I am unsure how to fix this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Steps to recreate:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Emails sent from external domain to internal domain is received by our email security platform and then forwarded to our on-premise mail server.&lt;/LI&gt;&lt;LI&gt;When the email is forwarded our email server then delivers the mail to the recipients mailbox and this is confirmed as successful.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Issues:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;A email with an attachment greater than approx. 3mb is hitting our email security platform and then queued for delivery.&lt;/LI&gt;&lt;LI&gt;When the attempt for delivery is made from the email gateway service, we get the following error repeatedly until the retry attempts expire. - &lt;STRONG&gt;Response 451 4.4.2 [internal] connection closed by remote host.&lt;/STRONG&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2020-08-06 05:32:57 PM&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Response: 451 4.4.2 [internal] connection closed by remote host&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2020-08-06 05:33:46 PM&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Delivery attempt #2&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2020-08-06 05:33:46 PM&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Recipient server:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What has been attempted:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;We have spoken with Microsoft Support and they have advised that once an email reaches the exchange transport service it is immediately passed to the recipient mailbox. Meaning no issues with configuration of transport rules and internal network.&lt;/LI&gt;&lt;LI&gt;It has been identified that these retry attempts of emails that have attachments never reach the exchange server.&lt;/LI&gt;&lt;LI&gt;The rejection error of 451 4.4.2 indicates that there is a network error between the security platform and the on premise exchange server that indicates the firewall as the cause.&lt;/LI&gt;&lt;LI&gt;Tried modifying the security policy by removing the IPS security profile and removing the service and application defaults of SMTP to be any/any with no success.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Help Required:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Really need some assistance troubleshooting the traffic coming inbound and why it is being rejected by the firewall when the email contains attachment &amp;lt;3mb.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Chris.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2020 22:30:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-reason-why-palo-rejecting-smtp-traffic-containing/m-p/342591#M85851</guid>
      <dc:creator>ccarter</dc:creator>
      <dc:date>2020-08-06T22:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: Possible Reason Why Palo Rejecting SMTP traffic containing attachments.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-reason-why-palo-rejecting-smtp-traffic-containing/m-p/342678#M85858</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/135151"&gt;@ccarter&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Are you seeing associated traffic logs indicating the traffic from the security provider at all? I'm always skeptical of security providers blaming the issue on the firewall when you've removed any associated security profile, removed application signatures, and can't see anything in the logs indicating an issue on your end.&lt;/P&gt;
&lt;P&gt;Try and get a packet capture before the firewall (you can of course take a PCAP directly on the firewall, just be sure to capture all stages of traffic flow, especially drop) and see if you are even receiving the traffic. That will tell you if it's actually getting stopped at the firewall (maybe it's getting dropped, but from what you've described the security rule you tested with should have really eliminated any firewall concerns).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 13:19:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-reason-why-palo-rejecting-smtp-traffic-containing/m-p/342678#M85858</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-08-07T13:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: Possible Reason Why Palo Rejecting SMTP traffic containing attachments.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-reason-why-palo-rejecting-smtp-traffic-containing/m-p/345801#M86392</link>
      <description>&lt;P&gt;Well, that was fun.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The cause was discovered at our WAN gateway. Diverting SMTP traffic into a different WAN interface, bang! Emails that were pending for delivery just bulk dumped into everyone's mailbox.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dealing with Telstra is an absolute nightmare so this was the only option. There was no way I was ever going to get a technical resource that has the knowledge to troubleshoot this issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was impressed with the methodical way that Palo Alto Support assisted from discovery through to analysis and packet capture, it was a breath of fresh air. For those that may find this interesting, these were the steps that they took to identify the issue was not with the Palo or internal network. Using the app override function to bypass Layer 7 inspection to rule this out was a very good thing to learn during this process.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;++&amp;nbsp;Pattern&amp;nbsp;in&amp;nbsp;both&amp;nbsp;packet&amp;nbsp;captures&amp;nbsp;is&amp;nbsp;same&amp;nbsp;that&amp;nbsp;is&amp;nbsp;when&amp;nbsp;layer7&amp;nbsp;inspection&amp;nbsp;was&amp;nbsp;going&amp;nbsp;on&amp;nbsp;and&amp;nbsp;when&amp;nbsp;we&amp;nbsp;did&amp;nbsp;app-override,&amp;nbsp;ruling&amp;nbsp;out&amp;nbsp;issues&amp;nbsp;with&amp;nbsp;layer7.&lt;BR /&gt;++&amp;nbsp;I&amp;nbsp;suspect&amp;nbsp;network&amp;nbsp;issue&amp;nbsp;based&amp;nbsp;on&amp;nbsp;following&amp;nbsp;observation:&lt;BR /&gt;&amp;gt;&amp;nbsp;Merge&amp;nbsp;receive1&amp;nbsp;and&amp;nbsp;transmit1&amp;nbsp;packet&amp;nbsp;captures.&lt;BR /&gt;&amp;gt;&amp;nbsp;Filter&amp;nbsp;packets&amp;nbsp;with&amp;nbsp;"tcp.port==39775&amp;nbsp;"&lt;BR /&gt;&amp;gt;&amp;nbsp;In&amp;nbsp;merged&amp;nbsp;pcap,&amp;nbsp;at&amp;nbsp;one&amp;nbsp;point&amp;nbsp;starting&amp;nbsp;from&amp;nbsp;frame&amp;nbsp;number:&amp;nbsp;5708,&amp;nbsp;issue&amp;nbsp;occurs.&amp;nbsp;This&amp;nbsp;packet&amp;nbsp;is&amp;nbsp;from&amp;nbsp;67.219.246.155(Symantec)--&amp;gt;xxx.xxx.xxx.xxx (Exchange&amp;nbsp;server&amp;nbsp;public&amp;nbsp;IP).&lt;BR /&gt;&amp;gt;&amp;nbsp;Next&amp;nbsp;expected&amp;nbsp;sequence&amp;nbsp;number&amp;nbsp;is&amp;nbsp;2431727156,&amp;nbsp;but&amp;nbsp;this&amp;nbsp;packet&amp;nbsp;never&amp;nbsp;arrives&amp;nbsp;on&amp;nbsp;firewall&amp;nbsp;and&amp;nbsp;such&amp;nbsp;will&amp;nbsp;not&amp;nbsp;reach&amp;nbsp;exchange&amp;nbsp;server.&lt;BR /&gt;&amp;gt;&amp;nbsp;Exchange&amp;nbsp;server&amp;nbsp;(or&amp;nbsp;any&amp;nbsp;TCP&amp;nbsp;based&amp;nbsp;application&amp;nbsp;will&amp;nbsp;work&amp;nbsp;based&amp;nbsp;on&amp;nbsp;dup&amp;nbsp;ack&amp;nbsp;to&amp;nbsp;tell&amp;nbsp;the&amp;nbsp;client&amp;nbsp;or&amp;nbsp;server&amp;nbsp;that&amp;nbsp;they&amp;nbsp;didn't&amp;nbsp;receive&amp;nbsp;an&amp;nbsp;expected&amp;nbsp;packet)&amp;nbsp;starts&amp;nbsp;sending&amp;nbsp;dup&amp;nbsp;ack&amp;nbsp;for&amp;nbsp;2431727156&amp;nbsp;and&amp;nbsp;this&amp;nbsp;goes&amp;nbsp;on&amp;nbsp;until&amp;nbsp;the&amp;nbsp;end&amp;nbsp;of&amp;nbsp;the&amp;nbsp;entire&amp;nbsp;TCP&amp;nbsp;stream&amp;nbsp;but&amp;nbsp;the&amp;nbsp;missing&amp;nbsp;packet&amp;nbsp;is&amp;nbsp;never&amp;nbsp;seen&amp;nbsp;again&amp;nbsp;from&amp;nbsp;the&amp;nbsp;Symantec&amp;nbsp;side&amp;nbsp;as&amp;nbsp;if&amp;nbsp;it&amp;nbsp;is&amp;nbsp;not&amp;nbsp;getting&amp;nbsp;the&amp;nbsp;"dup&amp;nbsp;acks"&amp;nbsp;from&amp;nbsp;Exchange&amp;nbsp;server.&amp;nbsp;&lt;BR /&gt;&amp;gt;&amp;nbsp;Firewall&amp;nbsp;has&amp;nbsp;these&amp;nbsp;dup&amp;nbsp;acks&amp;nbsp;in&amp;nbsp;its&amp;nbsp;transmit&amp;nbsp;stage&amp;nbsp;which&amp;nbsp;means&amp;nbsp;firewall&amp;nbsp;is&amp;nbsp;sending&amp;nbsp;out&amp;nbsp;towards&amp;nbsp;Symantec&amp;nbsp;side.&lt;BR /&gt;&amp;gt;&amp;nbsp;No&amp;nbsp;drops&amp;nbsp;seen&amp;nbsp;in&amp;nbsp;drop1&amp;nbsp;packet&amp;nbsp;capture&amp;nbsp;for&amp;nbsp;this&amp;nbsp;port.&lt;BR /&gt;&lt;BR /&gt;Next&amp;nbsp;Action&amp;nbsp;Plan:&lt;BR /&gt;=============&lt;BR /&gt;++&amp;nbsp;This&amp;nbsp;now&amp;nbsp;needs&amp;nbsp;to&amp;nbsp;be&amp;nbsp;checked&amp;nbsp;between&amp;nbsp;Symantec&amp;nbsp;and&amp;nbsp;Firewall.&amp;nbsp;A&amp;nbsp;packet&amp;nbsp;capture&amp;nbsp;on&amp;nbsp;intermediate&amp;nbsp;devices&amp;nbsp;can&amp;nbsp;tell&amp;nbsp;where&amp;nbsp;did&amp;nbsp;the&amp;nbsp;missing&amp;nbsp;packet&amp;nbsp;go.&amp;nbsp;Simultaneous&amp;nbsp;packet&amp;nbsp;captures&amp;nbsp;can&amp;nbsp;be&amp;nbsp;done&amp;nbsp;on&amp;nbsp;intermediate&amp;nbsp;device&amp;nbsp;and&amp;nbsp;PA-FW.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Next step, get rid of Telstra.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 04:55:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-reason-why-palo-rejecting-smtp-traffic-containing/m-p/345801#M86392</guid>
      <dc:creator>ccarter</dc:creator>
      <dc:date>2020-08-28T04:55:38Z</dc:date>
    </item>
  </channel>
</rss>

