Skip to main content

SMTP Restrictions automatically disables after enabling – affecting all 5 cPanel servers on 138.0

Comments

4 comments

  • cPRex Jurassic Moderator

    Hey there!  Thanks for bringing this up.  I was able to confirm the behavior and I've created case CPANEL-56968 for our developers to look into this.  I've also linked this thread to the case so I'll be sure to post any updates once I hear something on my end.

    0
  • Pathfinder

    I just noticed the same issue on 2 servers that were updated this morning. The smtp restriction is disabled, I enable it then run the security Advisor again and it shows disabled.

    0
  • Adam

    I'm seeing the same. It seems in my case:

    cPanel's SMTP script is failing because /etc/sysconfig/nftables.conf contains Imunify360-generated xt match "set" compatibility rules that the native nft loader cannot reload.

    The missing SMTP marker file and inactive service are consequences, not the root problem.

    What is happening

    1. Imunify360 installs working firewall rules through iptables-nft.
    2. cPanel's SMTP script exports the complete active ruleset into /etc/sysconfig/nftables.conf.
    3. That export includes Imunify360 compatibility expressions such as:
    xt match "set"
     
    1. cPanel then runs:
     
    systemctl restart nftables
    1. Native nft cannot reload those compatibility expressions.
    2. The restart fails, so cPanel rolls SMTP Restrictions back to disabled.

     

    My understanding is that Imunify360 SMTP Traffic Management is separately managed from WHM SMTP Restrictions and can restrict outbound SMTP connections, with whitelist support for users that require direct SMTP access. (WHM > Plugins > Imunify360 > Settings > SMTP Traffic Management)

    So it seems the solution may be to use that functionality instead? 

    0
  • cPRex Jurassic Moderator

    Adam - while there is a separate issue with nftables, it seems this is a unique problem so I created a separate case for it.

    0

Please sign in to leave a comment.