Request for assistance: Firewall rules for BI email notifications

Joined
Mar 4, 2020
Messages
3
Reaction score
1
Long time lurker, first time poster.

I have a BI server and cameras running on an isolated vlan with no internet access. Remote access has been configured on EdgeRouter 4 to only allow that vlan interface to communicate with connections coming from my MainPC IP address (on different VLAN). The switching is handled by my managed switch. So far everything is great and I can access via a Remote Desktop session from my PC or via an OpenVPN that I configured through my router.

Unfortunately, getting the email notifications through the firewall has proved to be more difficult than I expected. Right now, if I allow all TCP/UDP traffic (soure=IP of BI server) into the vlan interface on the router, the push and email notifications appear to work correctly. When I try to tweak that wide open rule to include a destination port = 465 and/or 587, the email notifications no longer work. I am at a loss as to what I am doing wrong. I have tried reading multiple guides on this and it seems like it should work, but maybe I am missing something obvious? It feels like maybe I am missing other ports that might be used in the SMTP process? I have tried multiple combinations, but nothing has seemed to work. I would obviously like keep things locked down as much as possible for this vlan and allowing all traffic from my BI Server does not see like a good option.

Any assistance would be very much appreciated.
Thank you, Joe.
 

biggen

Known around here
Joined
May 6, 2018
Messages
2,595
Reaction score
2,903
Have you tried port 25? Open that up and try again.
 
Joined
Mar 4, 2020
Messages
3
Reaction score
1
@biggen Thank you for the quick response, however, that advice did not seem to fix my issue. I am continuing to look at guides on how to allow traffic for a specific port on the "IN"bound interface for an EdgeRouter4 and it seems like I this should work. So frustrating. Thanks again for trying to help!
 

biggen

Known around here
Joined
May 6, 2018
Messages
2,595
Reaction score
2,903
Are you opening up both TCP and UDP for those ports?
 

biggen

Known around here
Joined
May 6, 2018
Messages
2,595
Reaction score
2,903
I don't use BI for email alerts but you would have had to give the address/ports of your SMTP provider to Blueiris in the Settings. What ports did you use?

Can you access the console of the Edgerouter and do a tcpdump or similar to see what traffic is being dropped when you try to send an email from that machine?
 
Joined
Mar 4, 2020
Messages
3
Reaction score
1
Edited

It has started working with all 3 ports specified in the same rule ports "587,465,25,53" (no spaces in the edge router UI). 53 is the port for DNS. The source was left as the IP for the BI server. Seems like the issue is resolved. Thank you again @biggen for your assistance!
 

biggen

Known around here
Joined
May 6, 2018
Messages
2,595
Reaction score
2,903
Ah I forgot about DNS. That is likely what got it working. Good for you!
 
Top