I check on domino side no more setting necessary . zimbra is at another subnet say 192.168.2.X

I just can figure out it is very related to postfix_smtpd_sasl_security_options in zmlocalconfig.

if i disable it or set it to wrong value e.g annoymous (invalid value) it can send finally. but empty or default value will have the following

any where i can tune to passthrough such parameters ??? even i clear all TLS/Autheication on the GUI does'nt help . ialso modifed the values in the zmconfig
e.g smtpd_relay_restrictions.cf smtpd_end_of_data_restrictions.cf smtpd_sender_restrictions.cf

It will cause more worst all myNetwrok already allow

Oct 8 15:52:38 zim01 postfix/smtps/smtpd[2240]: Anonymous TLS connection established from mail.domino.com[]: SSLv3 with cipher RC4-MD5 (128/128 bits)
Oct 8 15:52:38 zim01 postfix/smtps/smtpd[2240]: NOQUEUE: reject: RCPT from mail.domino.com []: 554 5.7.1 <testing@us.domino.com>: Recipient address rejected: Access denied; from=<test@domino.com> to=<testing@us.dominocom> proto=ESMTP helo=<mail.domino.com>
Oct 8 15:52:38 zim01 postfix/smtps/smtpd[2240]: disconnect from mail.domino.com[]