Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

How to block SMTP or port 25 with SEP firewall?

Updated: 21 May 2010 | 5 comments
wroot's picture
0 0 Votes
Login to vote

Is this possible to achieve such thing with built-in SEP firewall? I cant figure out how to form a rule for this. I need to block spambots to send direct emails from our network bypassing the legit SMTP server.

Comments

pete_4u2002's picture
20
Mar
2009
0 Votes 0
Login to vote

Hi, this is the desktop level

Hi,

this is the desktop level firewall. I guess you might need to look for netwrok level firewall with proper spam protection technology.

Pete!

Aniket Amdekar's picture
22
May
2009
0 Votes 0
Login to vote

I think Symantec Antispam

I think Symantec Antispam products will be the choice you are looking for. I agree with Pete, this is a client level firewall. What you ned is an antispam product.

Cheers,
Aniket

mon_raralio's picture
22
May
2009
0 Votes 0
Login to vote

.

Pete is right and Aniket is right for saying that Pete is right. :D
Add an appliance/server for spam protection.

But if you still want to go with this...here goes:

Go to SEP Policies > Firewall > Rules
Click on add rule or add blank rule, I chose blank rule. Rename it to whatever you want , click on the icon on the service column and select the port or service you want. Select the other options for the other columns as well.

Will you be using the standard SMTP port or assign a custom one?

“Your most unhappy customers are your greatest source of learning.”

thatdude's picture
22
May
2009
0 Votes 0
Login to vote

If your trying to restrict

If your trying to restrict what SMTP servers the clients can communicate with then create a rule that only allows SMTP to your know servers. Next rule is to block all other SMTP traffic or if you use a deny all at the end of your firewall ruleset it will catch it then.

wroot's picture
25
May
2009
0 Votes 0
Login to vote

We will have additional

We will have additional filtering software in the near future, but so far i want to reduce the chance of spambots working. So, i'm able to block outgoing traffic to a remote TCP 25 port. Outlook stops sending letters, at least. Of course, maliciuos software can use non-default ports.

I'm unable to create the exception for this rule to allow legitimate traffic to TCP 25 port. I'm creating the rule and specifying Remote Host - DNS domain - *.provider.com (our smtp is smtp.provider.com) and leaving the Action Allow. I have tried to put this rule before and after the blocking rule. But Outlook still cant send a letter.