{"id":1014,"date":"2021-01-06T11:28:38","date_gmt":"2021-01-06T17:28:38","guid":{"rendered":"http:\/\/zewwy.ca\/?p=1014"},"modified":"2021-01-06T11:28:38","modified_gmt":"2021-01-06T17:28:38","slug":"palo-alto-networks-email","status":"publish","type":"post","link":"https:\/\/zewwy.ca\/index.php\/2021\/01\/06\/palo-alto-networks-email\/","title":{"rendered":"Palo Alto Networks &#8211; Email"},"content":{"rendered":"<h1 style=\"text-align: center;\"><span class=\"ez-toc-section\" id=\"Story\"><\/span>Story<span class=\"ez-toc-section-end\"><\/span><\/h1>\n<p>Well back to work, so what other than another story of fun times troubleshooting what should be a super simple task. When I was hit with a delayed greyed out screen on the management UI and the subsequent error.<\/p>\n<p>&#8220;Unable to send email via gateway (email server IP)&#8221;<\/p>\n<h2 style=\"text-align: center;\"><span class=\"ez-toc-section\" id=\"The\"><\/span>The<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h2 style=\"text-align: center;\"><span class=\"ez-toc-section\" id=\"Hunt\"><\/span>Hunt<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Let&#8217;s see if others have hit this problem:<\/p>\n<p><a href=\"https:\/\/live.paloaltonetworks.com\/t5\/general-topics\/unable-to-send-email-alerts\/td-p\/336329#\">First ones a dead end.<\/a><\/p>\n<p><a href=\"https:\/\/knowledgebase.paloaltonetworks.com\/KCSArticleDetail?id=kA10g000000ClwmCAC\">Second<\/a> and <a href=\"https:\/\/knowledgebase.paloaltonetworks.com\/KCSArticleDetail?id=kA10g000000ClwSCAS\">Third<\/a> basically state to ensure legit email addresses are applied to both to and addition to fields. My case I know the only one email to address is fine.<\/p>\n<p>And finally the <a href=\"https:\/\/knowledgebase.paloaltonetworks.com\/KCSArticleDetail?id=kA10g000000ClUiCAK\">How to By Palo Alto Networks themselves.<\/a><\/p>\n<p>Well that&#8217;s annoying, bascially tell you to ensure the email server is accessible but they do so from other devices cause the PA can&#8217;t even do a telnet test&#8230; uhh ok useless, I know it&#8217;s open.<\/p>\n<h2 style=\"text-align: center;\"><span class=\"ez-toc-section\" id=\"Things_to_Know\"><\/span>Things to Know<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>I had contacted my buddy who specializes in PA firewalls. There are some things to note.<\/p>\n<ol>\n<li><a href=\"https:\/\/docs.paloaltonetworks.com\/pan-os\/8-1\/pan-os-admin\/networking\/service-routes.html\">Service Routing<\/a><br \/>\nBy default all traffic from the firewall, will go out the MGMT interface. Unless otherwise specified. In my case I was using a Service Route for Email to use the interface that was acting as the gateway for the subnet in which the email server was residing.<\/li>\n<li><a href=\"https:\/\/knowledgebase.paloaltonetworks.com\/KCSArticleDetail?id=kA10g000000ClTHCA0\">Intrazone and Interzone Rules<\/a><br \/>\nBy default if traffic doesn&#8217;t hit any rule it will be dropped, watch the video by Joe Delio for greater in-depth understanding.<\/li>\n<\/ol>\n<h2 style=\"text-align: center;\"><span class=\"ez-toc-section\" id=\"The_Solution\"><\/span>The Solution<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Now even though I had a &#8220;clean up&#8221; rule as stated by Joe. I was still not seeing the traffic being blocked (and I know it was being blocked).<\/p>\n<p>Once my buddy told me to override the intrazone rule and enabled logging on that rule, I was finally able to see the packets being dropped by the PAN firewall within the Traffic Logs\/Session Logs.<\/p>\n<p>Sure enough it was my own mistake as I had forgot to extent an existing rule which should have had the PAN&#8217;s gateway IP within it. After I noticed this I extended the rule to allow SMTP port 25 from the PA IP (not the mgmt IP) I was able to send emails from the PAN firewall.<\/p>\n<p>Hope this helps someone.<\/p>\n<p>Also note I ensured a dedicated receive connector on the email server to ensure the email would be allowed to flow though.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Story Well back to work, so what other than another story of fun times troubleshooting what should be a super simple task. When I was hit with a delayed greyed out screen on the management UI and the subsequent error. &#8220;Unable to send email via gateway (email server IP)&#8221; The Hunt Let&#8217;s see if others &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/zewwy.ca\/index.php\/2021\/01\/06\/palo-alto-networks-email\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Palo Alto Networks &#8211; Email&#8221;<\/span><\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"sfsi_plus_gutenberg_text_before_share":"","sfsi_plus_gutenberg_show_text_before_share":"","sfsi_plus_gutenberg_icon_type":"","sfsi_plus_gutenberg_icon_alignemt":"","sfsi_plus_gutenburg_max_per_row":"","footnotes":""},"categories":[127,8],"tags":[235,161],"class_list":["post-1014","post","type-post","status-publish","format-standard","hentry","category-palo-alto-networks","category-server-administration","tag-email","tag-pan"],"_links":{"self":[{"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/posts\/1014","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/comments?post=1014"}],"version-history":[{"count":1,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/posts\/1014\/revisions"}],"predecessor-version":[{"id":1015,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/posts\/1014\/revisions\/1015"}],"wp:attachment":[{"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/media?parent=1014"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/categories?post=1014"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/tags?post=1014"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}