Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Mails (O365) does not work with the below rule

    Scheduled Pinned Locked Moved Firewalling
    15 Posts 5 Posters 1.4k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • slkamathS Offline
      slkamath @KOM
      last edited by

      @kom Ok. Thank you. I will check. If any doubt again I will ping.

      Once again thanks for your valuable support @johnpoz @KOM

      1 Reply Last reply Reply Quote 0
      • JKnottJ Offline
        JKnott @slkamath
        last edited by

        @slkamath said in Mails (O365) does not work with the below rule:

        We are using Port POP

        If you have multiple devices, you probably want to use imap or imaps. This will allow all devices to see all messages and not worry about which one an email was sent from.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        slkamathS 1 Reply Last reply Reply Quote 0
        • slkamathS Offline
          slkamath @JKnott
          last edited by

          @jknott Ok. Thanks for your reply.

          Many users uses IMAP, but few users we have set as POP3.

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ Offline
            johnpoz LAYER 8 Global Moderator @slkamath
            last edited by

            And what are your imap settings in thunderbird?

            Something like this

            likethis.png

            Just the first setup I found for thunderbird and office365

            I have not used thunderbird for YEARS!!!

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 25.07 | Lab VMs 2.8, 25.07

            slkamathS 1 Reply Last reply Reply Quote 0
            • slkamathS Offline
              slkamath @johnpoz
              last edited by slkamath

              @johnpoz Thank you.

              Thunderbird Mail Setting.

              IMAP - 993 - outlook.office365.com - SSL/TLS
              SMTP - 587 - smtp.office365.com - STARTTLS
              POP - 995 - outlook.office365.com - SSL/TLS

              I recently setup pfBlockerNG & rule in firewall, from that time onwards it is not working.

              Firewall Rule:
              5.png

              I disabled this rule, then it is working.

              Anything I have change to work this rule?

              ahking19A 1 Reply Last reply Reply Quote 0
              • ahking19A Offline
                ahking19 @slkamath
                last edited by

                @slkamath Which rule did you disable? The allow DNS rule or the block DNS rule?

                Looking at the rule traffic they are both 0/0 B so no traffic is hitting those rules.

                192.168.3.3 is your local DNS server and it is running and is what is handed out to DHCP clients. If DNS was the problem you would be seeing more problems than just Thunderbird email access.

                johnpozJ slkamathS 2 Replies Last reply Reply Quote 0
                • johnpozJ Offline
                  johnpoz LAYER 8 Global Moderator @ahking19
                  last edited by

                  show us snips of rules doesn't help us help you.. Rules are evaluated top down, first rule to trigger wins, no other rules are evaluated. With seeing the full rule list and understanding rules with aliases and say this 192.168.3.3 is another vlan running some dns - like pihole or something.

                  It is pretty much impossible to help you.. Creating a pfblocker rule - that is what in the floating tab.. Yeah that for sure could be blocking where your trying to go, etc. etc..

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 25.07 | Lab VMs 2.8, 25.07

                  slkamathS 1 Reply Last reply Reply Quote 0
                  • slkamathS Offline
                    slkamath @ahking19
                    last edited by

                    @ahking19 Thanks for your reply.

                    Only problem is thunderbird. Internet is working fine in all the clients.

                    1 Reply Last reply Reply Quote 0
                    • slkamathS Offline
                      slkamath @johnpoz
                      last edited by slkamath

                      @johnpoz Thank you so much for your reply.

                      192.168.3.3 is pfsense IP. I am attaching firewall rules pic to understand better.

                      LAN Rules:

                      6.png

                      I have created alias for each department. Those have only mail access for them only mail ports are allowed (587, 993, 995), here 192.168.3.3 DNS rule is disabled. with this rule no-one can access mails.

                      8.png

                      others I have given all ports access.

                      9.png

                      In DHCP setting apart from 192.168.3.3 i have not mentioned any other DNS.

                      10.png

                      Floating Rules:

                      7.png

                      Now no one is accessing so in firewall LAN Rules it shows 0/0B.

                      ahking19A 1 Reply Last reply Reply Quote 0
                      • ahking19A Offline
                        ahking19 @slkamath
                        last edited by

                        @slkamath

                        I'm not sure I understand what the separate rules for departments are for. Currently all departments have the same access permissions set - IPv4 TCP/UDP Any Any. If you want to treat departments differently look at creating VLANs for each.

                        What IP(s) or network(s) does alias "Allow_Browsing_Servers" contain?

                        This is only rule that traffic is hitting on. Rules are evaluated top down, first match wins. For example Directors and MD traffic will never hit your rule with "MailPorts". They have already been granted access to anywhere in the rule above.

                        What IP(s) or network(s) does alias "MailIP" contain?

                        Are you using static IPs for all the client workstations? Your DHCP scope only has 3 addresses in it.

                        johnpozJ 1 Reply Last reply Reply Quote 0
                        • johnpozJ Offline
                          johnpoz LAYER 8 Global Moderator @ahking19
                          last edited by

                          He also has pfblocker floating rules that could very well be blocking.. And still hasn't shown what he is using for auth.. From what reading you have to be using oauthv2, etc.

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 25.07 | Lab VMs 2.8, 25.07

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.