Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Which ports to open for email server

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 3 Posters 627 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      robina80
      last edited by

      hi all,

      really dumb question but here goes,

      my default rule is to block all traffic and protocols to/from anywhere

      i have made an email server and it uses TCP 25 (SMTP for postfix), 143 (IMAP for dovecot) and 443 (HTTPS for afterlogic ie webmail)

      obviously i know to create a NAT port forward to the email server with those ports but do i need to create an outbound rule for it aswell so those ports can see out ie the internet?

      many thanks,

      rob

      1 Reply Last reply Reply Quote 0
      • V Offline
        viragomann
        last edited by

        No, you don't need any outbound NAT rule for incoming connections.

        However, postfix will also establish outbound connections for sending mails out. For these you need an outbound NAT rule, but for the WAN interface pfSense sets the outbound NAT automatically by default.

        1 Reply Last reply Reply Quote 0
        • R Offline
          robina80
          last edited by

          im thinking SMTP for both inbound/outbound traffic to email server, so it can send/recieve email from other smtp servers

          IMAP and HTTPS just inbound so people can access there emails via imap or https for webmail

          1 Reply Last reply Reply Quote 0
          • S Offline
            Soyokaze
            last edited by

            You should have 3 NAT rules (25, 143, 443) for external access, and 1 outbound rule (25) on LAN interface (for outbound SMTP).
            You do not need to create rules for "reply" traffic for external connections, they managed automagically.

            Need full pfSense in a cloud? PM for details!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.