kennysarmy Posted 4 hours ago Posted 4 hours ago Hi all, We're reviewing old service accounts and legacy authentication in our Microsoft 365 tenant and have found that our on-prem Smoothwall is still using an AD-synced Microsoft 365 account to send its scheduled reports and Monitor alerts. The current configuration is essentially: Smoothwall → smtp.office365.com:587 → TLS + SMTP AUTH → Microsoft 365 Smoothwall stores the username/password of a dedicated account (service_notifications) and authenticates to Exchange Online using SMTP AUTH. The same account is currently also used by Veeam, although we're treating that separately as Veeam has more modern authentication options. We asked Smoothwall Support whether Maiden-38/Newport supports OAuth 2.0 for Microsoft 365 SMTP. They've confirmed that it doesn't. Smoothwall supports SMTP AUTH/TLS with username/password, but not OAuth/Modern Authentication for this function. Their suggested alternative, if we want to remove the basic-authenticated credentials, is to use an SMTP relay. Our proposed approach therefore is: Smoothwall → Microsoft 365 SMTP relay → Exchange Online Rather than Smoothwall authenticating with a Microsoft 365 username/password, we'd create/configure the appropriate Exchange Online inbound connector and identify/authorise the school's sending connection by our fixed public IP (assuming that is suitable in our environment). Smoothwall would send to our Microsoft 365 MX endpoint over port 25 without SMTP AUTH. We'd test this alongside the existing configuration before removing anything. Once proven, Smoothwall would no longer need the service_notifications credentials. We'd then deal separately with Veeam and, once nothing needs the old SMTP AUTH account, disable/retire it. Has anyone else running on-prem Smoothwall with Microsoft 365 done this? In particular, I'd be interested to know: whether Microsoft 365 SMTP relay via an IP-restricted inbound connector is the approach others are using; whether there are any Smoothwall-specific gotchas with this; whether anyone has found a better solution that avoids maintaining an on-prem SMTP relay server; whether outbound TCP 25 or filtering/NAT caused any issues; and whether there are any security concerns or additional restrictions you'd recommend putting around the connector. I'm particularly keen not to stand up and maintain an internal SMTP server purely to solve this if Exchange Online's SMTP relay functionality can do the job securely. Any experiences or suggestions welcome.
Joeloman Posted 2 hours ago Posted 2 hours ago I don't know if you have Cloud Filter? However, sending out alerts via Cloud Filter is both safer and faster. https://kb.smoothwall.com/hc/en-us/articles/15280289798684-Manage-Instant-Safeguarding-Alerts-from-Cloud-Filter In my opinion, it is better to use the reports in Cloud Filter, and the information on the dashboard is often sufficient. If you do need a specific report, it is easy to create one. Another solution is to use https://www.smtp2go.com , which is free for smaller customers.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now