<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA and mail server  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-and-mail-server/m-p/712655#M1007601</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This sample configuration demonstrates how to set up the PIX Firewall for access to a mail server located on the Demilitarized Zone (DMZ) network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806745b8.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806745b8.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Apr 2007 17:58:31 GMT</pubDate>
    <dc:creator>bwilmoth</dc:creator>
    <dc:date>2007-04-16T17:58:31Z</dc:date>
    <item>
      <title>ASA and mail server</title>
      <link>https://community.cisco.com/t5/network-security/asa-and-mail-server/m-p/712654#M1007600</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an ASA 5520 as the gateway firewall with the public address of xxx.xxx.xxx.060.  &lt;/P&gt;&lt;P&gt;I do a static NAT to a GroupWise mail server with the public address of xxx.xxx.xxx.050&lt;/P&gt;&lt;P&gt;Using the following statement:  static (DIA_INSIDE,DIA_OUTSIDE) Groupwise_Pub Groupwise netmask 255.255.255.255.   Everything works just fine with this configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I recently purchased a spam firewall for inbound mail filtering.  It has the private address of Spamfilter.    I use the following port forwarding statement to pass inbound mail through the spam filter.  &lt;/P&gt;&lt;P&gt;static (DIA_INSIDE,DIA_OUTSIDE) tcp Groupwise_Pub smtp Spamfilter smtp netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;And this following to allow web access to the real mail server. 	&lt;/P&gt;&lt;P&gt;static (DIA_INSIDE,DIA_OUTSIDE) tcp Groupwise_Pub https Groupwise https netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All inbound still works just fine. However, the outbound mail now has the source address of xxx.xxx.xxx.060 rather that xxx.xxx.xxx.050 which it should be.  There is no PTR record for xxx.xxx.xxx.060 so most mail providers rejects my mail.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The question is:  What are the ramifications of changing the physical address of the DIA_OUTSIDE interface from xxx.xxx.xxx.060 to xxx.xxx.xxx.050 and then port forward as needed as this would place the address xxx.xxx.xxx.050 in the mail headers as the source address and resolve the PTR record problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glenn Anderson&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:glennanderson@wcps.org" target="_blank"&gt;glennanderson@wcps.org&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:58:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-and-mail-server/m-p/712654#M1007600</guid>
      <dc:creator>ke4clu</dc:creator>
      <dc:date>2019-03-11T09:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA and mail server</title>
      <link>https://community.cisco.com/t5/network-security/asa-and-mail-server/m-p/712655#M1007601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This sample configuration demonstrates how to set up the PIX Firewall for access to a mail server located on the Demilitarized Zone (DMZ) network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806745b8.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806745b8.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2007 17:58:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-and-mail-server/m-p/712655#M1007601</guid>
      <dc:creator>bwilmoth</dc:creator>
      <dc:date>2007-04-16T17:58:31Z</dc:date>
    </item>
  </channel>
</rss>

