Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Configuring exchange - port forwards

    Scheduled Pinned Locked Moved NAT
    18 Posts 3 Posters 4.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD
      Derelict LAYER 8 Netgate
      last edited by

      Almost all ISPs block outbound port 25 on residential service.  Sorry.

      About the only thing you can do is configure your mail server to send all mail to your ISPs mail server.  Usually called a "Smart Host."  You might also configure it to connect to an arbitrary smart host on 587 and provide authentication.  Something like smtp.google.com might be a good choice for that.

      Then there are thinks like SPF records, etc you'll want to get right in your DNS.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • R
        robina80
        last edited by

        Great thanks for your help much appreciated

        So theres no way to send my emails out port 587?

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          If you can configure exchange to connect to a specific mail server on 587, authenticate, and send all your mail, sure.

          But you can't do it the same as port 25 because, by convention, servers listening on 587 have to require authentication before accepting mail submissions.  You can define a smart host on 587, authenticate to it, and send all outbound mail.  Then you rely on them to forward it to the appropriate SMTP host.

          You might also have a specific mail server at your ISP that will accept unauthenticated connections on 25 and deliver your mail.  They would specifically pass traffic from you to that server on 25.

          In a nutshell, if you can't go out on tcp/25, your mail server can't be used to look up MX records and send outbound mail to the correct host.  You have to send it all to one server and let them do the MX lookups and deliver it.

          You might run into restrictions on what domains can be used as From: addresses, etc.  It really all depends.  Some don't care, some are real jerks and do stupid stuff.

          Some might even block inbound port 25 which is just plain brainless.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • R
            robina80
            last edited by

            As when I used hmail server I could send and receive on port 587 SMTP so I really don't understand why exchange wont send out using port 587 as hmail worked perfectly using that port

            1 Reply Last reply Reply Quote 0
            • DerelictD
              Derelict LAYER 8 Netgate
              last edited by

              What happens when you telnet from your exchange server to the mail server on port 587?

              Note that outbound connections such as sending mail don't require a port forward.  They only need outbound NAT (if NAT is necessary).

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                @robina80:

                As when I used hmail server I could send and receive on port 587 SMTP so I really don't understand why exchange wont send out using port 587 as hmail worked perfectly using that port

                If you are saying you could send mail to arbitrary mail servers on 587, things weren't working like you think they were.  Most mail servers on the internet require authentication before you can send ANY mail through them - even to the local domains they serve.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • R
                  robina80
                  last edited by

                  when i have my exchange server on at home, from work i can telnet in on port 587 (my new SMTP send connector) and i get a reply back (220 mail server ready at your service) but when i had my exchange using port 25 (SMTP send connector) i didn't get a response so i can safely say virgin media block port 25 for outgoing emails

                  i can receive emails when i make my send connector SMTP port 25 but when i make it port 587 i cant even receive nor even send but i can telnet into it which i dont understand atall

                  1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate
                    last edited by

                    I'm going to have to step back and let you decide what ports you want open from where to where.  When you figure that out, I'll be happy to help you get pfSense doing the right thing.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • R
                      robina80
                      last edited by

                      thank you Derelict,

                      i do want to make my SMTP send connector port 587 as virgin media block outbound port 25

                      1 Reply Last reply Reply Quote 0
                      • DerelictD
                        Derelict LAYER 8 Netgate
                        last edited by

                        Then do that.  It should require no configuration in pfSense.  I can't help you with configuring exchange.  exim/sendmail/postfix maybe, but not exchange.  good luck.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • R
                          robina80
                          last edited by

                          thank you, you have been very helpful

                          rob

                          1 Reply Last reply Reply Quote 0
                          • F
                            FlashPan
                            last edited by

                            @robina80:

                            as virgin media block outbound port 25

                            Hi,

                            Sorry for maybe putting the cat amongst the pigeons but I am on virginmedia cable and they do not block port 25, I have my test exchange 2010 box running fine with minimal configuration and on port 25

                            1 Reply Last reply Reply Quote 0
                            • R
                              robina80
                              last edited by

                              mmm…

                              reason why i am asking if 25 is blocked if i run a telnet command from the internet i cant connect to my mail server using 25 but i can when i change it to 587, it says 220 my mail server is ready

                              obviously  i port forward the correct ports 25/587 to my exchange server at the time im testing the above command

                              as every time i make my send connector 25 i cant send but i can receive, guess i will try with exchange 2010

                              1 Reply Last reply Reply Quote 0
                              • DerelictD
                                Derelict LAYER 8 Netgate
                                last edited by

                                @robina80:

                                mmm…

                                reason why i am asking if 25 is blocked if i run a telnet command from the internet i cant connect to my mail server using 25 but i can when i change it to 587, it says 220 my mail server is ready

                                obviously  i port forward the correct ports 25/587 to my exchange server at the time im testing the above command

                                as every time i make my send connector 25 i cant send but i can receive, guess i will try with exchange 2010

                                But what you're saying is contradictory.  If you change to port 25 and "can receive" that means other mail servers can make the connection to you on 25.  Which is the opposite of your telnet test experience.

                                Chattanooga, Tennessee, USA
                                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                1 Reply Last reply Reply Quote 0
                                • R
                                  robina80
                                  last edited by

                                  Hi all

                                  Good news its working, i will quickly describe what i did

                                  I found out one of the services "MS EXCH Mailbox Transport Submission" wasnt running when i listed in order of automatic services

                                  I made my send connector back in using port 25 instead of 587 as mails would not send

                                  Once i did that my messages went one by one to my sent items in OWA and i had about 23 emails in my gmail inbox

                                  Also i did this -

                                  http://exchangekb.com/2014/03/19/exchange-2013-emails-stuck-in-drafts

                                  I added for internal dns my domain controller ip and in external dns my isp's dns and google's dns

                                  http://exchangemaster.wordpress.com/2014/06/10/mails-stuck-in-the-draft-folder

                                  http://technet.microsoft.com/en-us/library/cc816856(v=ws.10).aspx

                                  I added my isp's dns and google's dns

                                  Really grateful for everones input so much appreciated all pointed me in the right direction and so glad got it sorted, only taken me a week!!!

                                  Rob

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.