Solved Test email rejected by smtp-proxy.3cx.com

Status
Not open for further replies.

Ted.D

Free User
Joined
Jun 16, 2021
Messages
11
Reaction score
0
I am setting up a 3CX instance for evaluation. The version is: Standard Annual 16.0.8.9. I'm using a Windows 10 Professional VM on Hyper-V as the operating system. I'm using a Sonicwall UTM appliance. It has been configured for the 3CX, and the Firewall Checker passes with no issues.

I'm having trouble setting up the email for notifications, welcome messages, etc. Trying to send a test email (multiple addresses in multiple domains attempted) yields the error message: "5.7.0 Denied". At least that means it's in an SMTP session with smtp-proxy.3cx.net. I have the Wireshark capture of the conversation between my 3CX instance and smtp-proxy.3cx.net. Since it's encrypted, I can't read beyond the beginning of the conversation. The corresponding error message in C:\ProgramData\3CX\Data\Logs\CloudServiceWatcher.log is:

2021/06/16 10:36:00.789|0015|Excpt(03)| MailKit.Security.AuthenticationException: 535: 5.7.0 Denied
---> MailKit.Net.Smtp.SmtpCommandException: 5.7.0 Denied

Without working email, there isn't a good way to continue the evaluation. Everything on the dashboard is green, so I'm assuming that the setup is OK. I would be grateful for any suggestions. Thanks.
 
You need to make sure Network External IP address matches - Settings - Network Settings

1. Your wan IP address
2. 3CX FQDN address

If it does not match, change the setting to the correct IP address if you have a fixed ip address or Dynamic Public IP

Also make sure port 2528 outbound is not blocked - https://www.3cx.com/docs/ports/
 
I thought about it for a bit, and realized that the outbound 3CX traffic NAT rule forwarded outbound 3CX traffic only for inbound 3CX traffic. Other outbound 3CX traffic was handled by the default NAT rule, which forwards most other outbound traffic through a different public IP. Once I changed the outbound 3CX NAT rule to handle all traffic from the 3CX host, then the test email was successful. That doesn't explicitly show up, on the dashboard (which does show the correct WAN IP), or in the 3CX documentation about network / firewall configuration. To put it another way, smtp-proxy.3cx.net requires that the email origination public IP address matches the public IP address to which the 3CX FQDN resolves. Thanks for your response; it was the nudge that I needed.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet