How to configure Firewall to allow HES to connect to LDAP server.

Description

How to configure Firewall to allow HES to connect to LDAP server.

Resolution

In order to get our Hosted Email Security (HES) to work with On-prem Firewall solutions, these are the necessary firewall settings that need to be configured to allow HES to work and block other traffic from using our services. Please also reference SonicWall Hosted Email Security FAQ.  As it will show more details regarding HOsted Email Security configurations. Also reference How To Configure LDAP And Enable DHA On HES


Create the following in order of appearance


  • Login to firewall.
  • Navigate  to Network | Services.
  •  Click on Service groups.
  •  Click on Add.
  •  Add LDAP and LDAPS.
  •  Name the file and save it.
    Image



Creating Address Objects

  • Navigate to Network | Address Objects.
  • Click on Add.
  • Type in the name and zone is Wan  Type is Network.
  •  Enter the following Network address for North America. 
  •  For EU customers IP is 173.240.221.0/24


Address Objects

  • Hosted IP a         173.240.210.0/255.255.255.0
  • Hosted IP b         173.240.213.0/255.255.255.0      
  • Hosted IP c          204.212.170.10
               Image




Add the Address Objects to an Address Group

  •  Click on Network | Address Objects | Address groups.
  •  Click on Add.
  •  Enter the name Hosted IPs
  •  Add the Hosted IP A, Hosted IP B, Hosted IP C to the group.
    Image



Nat Policies(for LDAP traffic  )


  • Navigate to Network | Nat Policies.
  •  Click on Add.
  •  It should look like the screen below.  


  • Any
  • Original
  • Public IP
  • Private IP 
  • LDAP+S
  • Original

    Image



Access Rules


  •  Navigate to Firewall | Access Rules.
  • Click on WAN to LAN.
  • Click Add.
  •  Type in the following access rules shown below.

Allow Rule

  • Wan
  • Lan
  • Hosted IPs
  • Public IP
  • LDAP+S
  • Allow    

Deny Rule

  • Wan
  • Lan
  • Any
  • Public IP
  • LDAP+S
  • Deny 

    TIP: Please make sure the Allow Rule has higher priority that Deny Rules.

    Image







    Image

This should configure the firewall to allow hosted to work. 


Related Articles

  • Invalid SFP Connected warning on SonicWall firewall when using supported 10G SFP+ Module
    Read More
  • How to exclude the domain from DHA scanning?
    Read More
  • Email Security: How to download the Outlook Junk Tool?
    Read More
not finding your answers?