Question : nat transalation on a sonicwall tz 170 device

I have a static public IP address and I am trying to deliver email via a sonicwall tz 170 device to a LAN network. The lan network is where the exchange server is.

How do I nat the public ip address to the exchange server's ip address in the internal lan? I have the SonicOS Standard.


Answer : nat transalation on a sonicwall tz 170 device

Short Answer:

  1. Create an "address object" on the SonicWALL for the LAN IP of your Exchange server. Name it something like InternalMailServer and use the IP address of your Exchange server. 
  2. Setup a port forward for inbound SMTP traffic addressed to your public IP address (same as your MX record on your public DNS registration) directing it to address object InternalMailServer . 
  3. Setup rules on the SonicWALL 
    1. Deny all SMTP from LAN to WAN. 
    2. Allow SMTP InternalMailServer in LAN zone to WAN. 
    3. Allow SMTP from WAN to InternalMail in LAN zone. 
  4. Make sure your MX record is defined/recorded with your public domain. 
  5. You should also have PTR record for your mail server. 

Regarding the SMTP rules, rules 1 & 2 restrict outbound SMTP traffic to ONLY your designated mail server.  This helps keep your mail server from being blocked as a result of in infected computer inside your network spamming using your firewall's public IP address. If you have a mail filter server, you will need to modify the above configuration after testing it successfully.

Note: Many of the SonicWALL appliances have a pretty good SMTP wizard supporting an internal mail server.  Said wizards walk you through most of the above steps and help "cover the bases".  Having used the wizard to setup your Exchange server traffic to/from the Internet; having taken care of your public DNS; and having tested SMTP traffic to/from your mail server and the outside world; then you can backup and modify the configuration (if needed) to support a mail filter server, if desired.

- Tom

Random Solutions  
programming4us programming4us