<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic not able to send/recieve email through pix in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/not-able-to-send-recieve-email-through-pix/m-p/613306#M1023835</link>
    <description>&lt;P&gt;hi, am very new to configuring pix firewall's so forgive me if it a silly mistake, i think ive misconfigured my acl because i have already turned off mailguard (no fixup smtp) and i am still not able to send/recieve any email from my internal exchange server(10.35.104.106) but i have access to the internet.&lt;/P&gt;&lt;P&gt;here's my config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 09:43:08 GMT</pubDate>
    <dc:creator>handley88</dc:creator>
    <dc:date>2019-03-11T09:43:08Z</dc:date>
    <item>
      <title>not able to send/recieve email through pix</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-send-recieve-email-through-pix/m-p/613306#M1023835</link>
      <description>&lt;P&gt;hi, am very new to configuring pix firewall's so forgive me if it a silly mistake, i think ive misconfigured my acl because i have already turned off mailguard (no fixup smtp) and i am still not able to send/recieve any email from my internal exchange server(10.35.104.106) but i have access to the internet.&lt;/P&gt;&lt;P&gt;here's my config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:43:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-send-recieve-email-through-pix/m-p/613306#M1023835</guid>
      <dc:creator>handley88</dc:creator>
      <dc:date>2019-03-11T09:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: not able to send/recieve email through pix</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-send-recieve-email-through-pix/m-p/613307#M1023840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please enter following commands-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no access-list outside_in permit tcp any host 194.74.152.164 eq smtp                                &lt;/P&gt;&lt;P&gt;no access-list outside_in permit tcp any host 194.74.152.164 eq www                                                                &lt;/P&gt;&lt;P&gt;no access-list outside_in permit tcp any host 194.74.152.164 eq domain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_in permit tcp any interface outside eq www                                                                &lt;/P&gt;&lt;P&gt;access-list outside_in permit tcp any interface outside eq domain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear xlate local 10.35.104.106&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Mar 2007 16:15:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-send-recieve-email-through-pix/m-p/613307#M1023840</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-03-07T16:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: not able to send/recieve email through pix</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-send-recieve-email-through-pix/m-p/613308#M1023850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi, ive changed my acl's so they read like this and now i have recieved one of the email i sent from my gmail account&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_in permit tcp any interface outside eq smtp&lt;/P&gt;&lt;P&gt;access-list outside_in permit tcp any interface outside eq www&lt;/P&gt;&lt;P&gt;access-list outside_in permit tcp any interface outside eq domain&lt;/P&gt;&lt;P&gt;access-list outside_in permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list outside_in permit icmp any any unreachable&lt;/P&gt;&lt;P&gt;access-list outside_in permit icmp any any time-exceeded&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Mar 2007 16:56:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-send-recieve-email-through-pix/m-p/613308#M1023850</guid>
      <dc:creator>handley88</dc:creator>
      <dc:date>2007-03-07T16:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: not able to send/recieve email through pix</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-send-recieve-email-through-pix/m-p/613309#M1023851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gr8 .. so things seem to be working now ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Mar 2007 17:16:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-send-recieve-email-through-pix/m-p/613309#M1023851</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-03-07T17:16:04Z</dc:date>
    </item>
    <item>
      <title>Re: not able to send/recieve email through pix</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-send-recieve-email-through-pix/m-p/613310#M1023855</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sorry my post was not very clear i now can recieve emails but not send&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Mar 2007 17:22:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-send-recieve-email-through-pix/m-p/613310#M1023855</guid>
      <dc:creator>handley88</dc:creator>
      <dc:date>2007-03-07T17:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: not able to send/recieve email through pix</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-send-recieve-email-through-pix/m-p/613311#M1023857</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ohh .. thats not good. I've gone through the configuration and its not supposed to block any outbound connections. Please make sure that your  mail server is configured correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, you can try chaning the maximum dns-length allowed-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no fixup protocol dns maximum-length 512&lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 1024&lt;/P&gt;&lt;P&gt;clear xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you try collecting syslogs at the time you are trying to send outbound mails?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Mar 2007 17:31:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-send-recieve-email-through-pix/m-p/613311#M1023857</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-03-07T17:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: not able to send/recieve email through pix</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-send-recieve-email-through-pix/m-p/613312#M1023858</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi, tryed changing max length on fixup dns with no luck, ive setup syslog and am geting lots of udp packets blocked from the server&lt;/P&gt;&lt;P&gt;ive attched the latest sho run and the output from syslog server during the time the emails were sent and checked the exchange server and messages are waiting to be sent and as soon as i remove the pix email are sent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks &lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2007 10:55:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-send-recieve-email-through-pix/m-p/613312#M1023858</guid>
      <dc:creator>handley88</dc:creator>
      <dc:date>2007-03-08T10:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: not able to send/recieve email through pix</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-send-recieve-email-through-pix/m-p/613313#M1023861</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi .. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Went through the logs and config and noticed a strange thing. Check the following syslog message-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%PIX-7-710005: UDP request discarded from 10.35.104.106/28536 to inside:10.35.104.100/domain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.35.104.106 is trying to send domain traffic to 10.35.104.100. Now if I've checked your config correctly, 10.35.104.100 is the IP address of inside interface of PIX .. right? Is the mail server set to contact PIX's inside interface IP for DNS resolution? If so, please have it point to a legitimate DNS server because PIX cannot do name resolutions. Please reset the mail server to use a DNS server like 4.2.2.2 and then check if mails flow out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Mar 2007 20:53:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-send-recieve-email-through-pix/m-p/613313#M1023861</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-03-09T20:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: not able to send/recieve email through pix</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-send-recieve-email-through-pix/m-p/613314#M1023863</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;i wiped the config on both the mail server and the pix and then reconfigured them both and now mail is flowing in and out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for all your help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Mar 2007 09:03:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-send-recieve-email-through-pix/m-p/613314#M1023863</guid>
      <dc:creator>handley88</dc:creator>
      <dc:date>2007-03-14T09:03:29Z</dc:date>
    </item>
  </channel>
</rss>

