Watchguard Firebox 700 and Some Related Issues

From: Dustin (dustin_dortch@hotmail.com)
Date: 05/28/02


From: dustin_dortch@hotmail.com (Dustin)
Date: 28 May 2002 07:19:48 -0700

Last Friday, we received a Watchguard Firebox 700, and I set it up.
Our current needs require we have 3 services available to the outside,
SMTP, RDP (Terminal Services), and PPTP. I currently have RDP setup
to our needs 100%. There are a few quirks with the SMTP, as we use
Exchange Server 5.5, and the SMTP is done via a proxy, and not port
forwarding. When I watch the Traffic Monitor, I keep seeing messages
about `removing unknown or denied header "Received"` and I have made
sure that is allowed in the config. Also plenty of errors on ESMTP
headers being removed. I do not want all of this ESMTP to be removed.
 I believe this is screwing up email with other mail servers running
Microsoft Exchange, as they communicate via ESMTP. The other issue is
PPTP. We are not using the firewall to provide the VPN services. I
just want to pass the PPTP traffic through the firewall to our NT 4
Server. I have allowed the forwarding of port 1723 and the IP
protocol 47. It is a no go. If I pull the firewall out, it works
great, put it in use, and it doesn't work, fairly simple.

Any suggestions would be greatly appreciated, thanks.

Dustin, Network+, MCP



Relevant Pages

  • Watchguard Firebox 700 and Some Related Issues
    ... SMTP, RDP, and PPTP. ... I do not want all of this ESMTP to be removed. ... We are not using the firewall to provide the VPN services. ...
    (comp.security.firewalls)
  • Re: Exchange behind WatchGuard Firewall
    ... If the server is in a DMZ there is definately a firewall involved. ... Proxy services usually only transmit standard SMTP and not extended SMTP ... | Subject: Re: Exchange behind WatchGuard Firewall ...
    (microsoft.public.exchange2000.connectivity)
  • Re: Exchange behind WatchGuard Firewall
    ... first article deals with sending SMTP out through the firewall. ... I don't believe SMTP will really be involved. ... Watchguard. ... > Watchguard firwalls usually come with a SMTP Proxy service running on ...
    (microsoft.public.exchange2000.connectivity)
  • Symantec Enterprise Firewall (SEF) SMTP proxy inconsistencies
    ... Symantec Enterprise Firewall (SEF) SMTP proxy inconsistencies ...
    (Bugtraq)
  • Re: Diff b/w cheap and expensive firewalls
    ... > You need to separate the idea that a router with NAT is a firewall from ... > what a real firewall is/does. ... > SMTP server. ...
    (comp.security.firewalls)