If you disabled that DNAT rule, Sophos UTM will scan all of the incoming emails before forwarding it to your internal Exchange server. Regarding outgoing emails, you have to configure Exchange send connector with SMTP address space * pointing to internal IP address of UTM:
↧