> Source: [sk166472](https://support.checkpoint.com/results/sk/sk166472)

# sk166472 - emails sent by Sophos/3rd Party postfix not received by Check Point MTA

| Property | Value |
|----------|-------|
| Solution ID | sk166472 |
| Date Created | 2020-06-17 |
| Last Modified | 2020-06-22 |
| Technical Level | Advanced |
| OS | Gaia |

## Symptoms

- * emails sent by Sophos/3rd Party postfix not received by Check Point MTA.
* Sophos/ 3rd Party postfix errors:  

  2020:04:15-15:28:20 fw-2 exim-out\[28090\]: 2020-04-15 15:28:20 \<\> Completed

  2020:04:15-15:28:22 fw-2 exim-in\[12529\]: 2020-04-15 15:28:22 SMTP connection from \<IP:port\> (TCP/IP connection count = 2)

  2020:04:15-15:28:22 fw-2 exim-in\[28094\]: 2020-04-15 15:28:22 TLS error on connection from \<IP:Port\> (SSL_accept): error:00000000:lib(0):func(0):reason(0)

  2020:04:15-15:28:22 fw-2 exim-in\[28094\]: 2020-04-15 15:28:22 TLS client disconnected cleanly (rejected our certificate?)

  2020:04:15-15:28:26 fw-2 exim-in\[12529\]: 2020-04-15 15:28:26 SMTP connection from \<IP:Port\> (TCP/IP connection count = 2)

  2020:04:15-15:28:26 fw-2 exim-in\[28100\]: 2020-04-15 15:28:26 TLS error on connection from \<IP:Port\> (SSL_accept): error:00000000:lib(0):func(0):reason(0)

  2020:04:15-15:28:26 fw-2 exim-in\[28100\]: 2020-04-15 15:28:26 TLS client disconnected cleanly (rejected our certificate?)

  2020:04:15-15:28:29 fw-2 exim-in\[28086\]: 2020-04-15 15:28:29 server_login authenticator failed for (User) \<IP:Port\>: 535 Incorrect authentication data (set_id=mail@domain..)

  2020:04:15-15:28:31 fw-2 exim-in\[28086\]: 2020-04-15 15:28:31 SMTP connection from (User) \<IP:Port\> closed by QUIT

  2020:04:15-15:28:40 fw-2 exim-in\[12529\]: 2020-04-15 15:28:40 SMTP connection from \<IP:Port\> (TCP/IP connection count = 1)

  2020:04:15-15:28:40 fw-2 exim-in\[28105\]: 2020-04-15 15:28:40 TLS error on connection from \<IP:Port\> (SSL_accept): error:00000000:lib(0):func(0):reason(0)
* No drops via command line:  

  #fw ctl zdebug + drop \| grep ":25"

## Cause

Errors that can be seen on "Sophos" device are related to "IPS blade".  

Protections from IPS blade are dropping the SMTP traffic from "Sophos" to the gateway.   

In this case, the Protections are:

* Bad SMTP Server Greeting.
* SMTP Starttls command.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
