<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: configuring cisco pix 506e firewall for mails problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/configuring-cisco-pix-506e-firewall-for-mails-problem/m-p/696287#M1024209</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi hemant,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you need the follwoing on the pix,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 25 192.168.1.2 25 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list out_in permit tcp any interface outside eq 25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-g out_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what this is doing ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;opening port 25 on pix's oustdie interface&lt;/P&gt;&lt;P&gt;the mx record of this mail server should point to the outside interface of the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope this takes care of your issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sushil.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Mar 2007 15:21:26 GMT</pubDate>
    <dc:creator>suschoud</dc:creator>
    <dc:date>2007-03-08T15:21:26Z</dc:date>
    <item>
      <title>configuring cisco pix 506e firewall for mails problem</title>
      <link>https://community.cisco.com/t5/network-security/configuring-cisco-pix-506e-firewall-for-mails-problem/m-p/696284#M1024206</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;I am Hemant, We have pix 506e firewall, D-link ADSL dsl-502t and my IBM xseries 236 server. &lt;/P&gt;&lt;P&gt;I have fix static live ip 59.181.103.220 which i have got ISP (MTNL), and the same ip is given in fqdn in &lt;A class="jive-link-custom" href="http://www.net4india.com" target="_blank"&gt;http://www.net4india.com&lt;/A&gt; (a company from where we have registered domaim name and taken space) &lt;/P&gt;&lt;P&gt;My problem is i am not able to send mail through my mail server (loyalindia.co.in)but i am receiving mails from any server. &lt;/P&gt;&lt;P&gt;My network design is as fallows:- &lt;/P&gt;&lt;P&gt;ADSL (WAN)59.181.103.220, ADSL (LAN)59.181.103.221. Pix 506e (out) 59.181.103.222, Pix 506e (in) 192.168.1.1. My domain mail server loyalindia.co.in (Exchange server) ip 192.168.1.2 &lt;/P&gt;&lt;P&gt;I am tryied with (ADSL)natting and without natting but the problem is same. &lt;/P&gt;&lt;P&gt;If i am removing the pix 506e and directly connecting the server to adsl i am able to receive and send mails properly&lt;/P&gt;&lt;P&gt;anybody who can support me?.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:41:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-cisco-pix-506e-firewall-for-mails-problem/m-p/696284#M1024206</guid>
      <dc:creator>hemanttandel</dc:creator>
      <dc:date>2019-03-11T09:41:30Z</dc:date>
    </item>
    <item>
      <title>Re: configuring cisco pix 506e firewall for mails problem</title>
      <link>https://community.cisco.com/t5/network-security/configuring-cisco-pix-506e-firewall-for-mails-problem/m-p/696285#M1024207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you verufy the fixup smtp ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you use exchange with ESMTP protocol disable the fixup with no fixup smtp.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roberto &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Mar 2007 13:14:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-cisco-pix-506e-firewall-for-mails-problem/m-p/696285#M1024207</guid>
      <dc:creator>ROBERTO TACCON</dc:creator>
      <dc:date>2007-03-05T13:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: configuring cisco pix 506e firewall for mails problem</title>
      <link>https://community.cisco.com/t5/network-security/configuring-cisco-pix-506e-firewall-for-mails-problem/m-p/696286#M1024208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Roberto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have given the command "no fixup protocol smtp" but it did not solved my problem.&lt;/P&gt;&lt;P&gt;Anyother command for pix which i can try. My network design is ok or it should be changed.&lt;/P&gt;&lt;P&gt;Design is as:&lt;/P&gt;&lt;P&gt;adsl (wan) 59.181.103.220, &lt;/P&gt;&lt;P&gt;adsl (lan)59.181.103.221, &lt;/P&gt;&lt;P&gt;cisco pix 506e (wan) 59.181.103.222, &lt;/P&gt;&lt;P&gt;cisco pix 506e (lan) 192.168.1.1, &lt;/P&gt;&lt;P&gt;Domain controler(loyalindia.co.in) mail server (Exchange 2003) ip is 192.168.1.2&lt;/P&gt;&lt;P&gt;is this network design ok &lt;/P&gt;&lt;P&gt;or i have to make some changes.&lt;/P&gt;&lt;P&gt;Please let me know. waiting for the reply.&lt;/P&gt;&lt;P&gt;Bye&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2007 04:59:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-cisco-pix-506e-firewall-for-mails-problem/m-p/696286#M1024208</guid>
      <dc:creator>hemanttandel</dc:creator>
      <dc:date>2007-03-08T04:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: configuring cisco pix 506e firewall for mails problem</title>
      <link>https://community.cisco.com/t5/network-security/configuring-cisco-pix-506e-firewall-for-mails-problem/m-p/696287#M1024209</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi hemant,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you need the follwoing on the pix,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 25 192.168.1.2 25 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list out_in permit tcp any interface outside eq 25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-g out_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what this is doing ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;opening port 25 on pix's oustdie interface&lt;/P&gt;&lt;P&gt;the mx record of this mail server should point to the outside interface of the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope this takes care of your issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sushil.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2007 15:21:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-cisco-pix-506e-firewall-for-mails-problem/m-p/696287#M1024209</guid>
      <dc:creator>suschoud</dc:creator>
      <dc:date>2007-03-08T15:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: configuring cisco pix 506e firewall for mails problem</title>
      <link>https://community.cisco.com/t5/network-security/configuring-cisco-pix-506e-firewall-for-mails-problem/m-p/696288#M1024210</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;no" it did not solved my problem.&lt;/P&gt;&lt;P&gt;should i changed the mx record, fqdn ip (59.181.103.220) which is register with the dns. &lt;/P&gt;&lt;P&gt;My static live ip 59.x.x.220&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My network Design is as: &lt;/P&gt;&lt;P&gt;adsl (wan) 59.x.103.220, &lt;/P&gt;&lt;P&gt;adsl (lan)59.x.103.221, &lt;/P&gt;&lt;P&gt;cisco pix 506e (wan) 59.x.103.222, &lt;/P&gt;&lt;P&gt;cisco pix 506e (lan) 192.168.1.1, &lt;/P&gt;&lt;P&gt;Domain controler(loyalindia.co.in) mail server (Exchange 2003) ip is 192.168.1.2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My config.&lt;/P&gt;&lt;P&gt;PIX Version 6.3(5)&lt;/P&gt;&lt;P&gt;interface ethernet0 auto&lt;/P&gt;&lt;P&gt;interface ethernet1 auto&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;enable password xxx&lt;/P&gt;&lt;P&gt;passwd xxx&lt;/P&gt;&lt;P&gt;hostname loyal&lt;/P&gt;&lt;P&gt;domain-name loyalfire.com&lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 512&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;no fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;fixup protocol tftp 69&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 59.x.103.221 adsl&lt;/P&gt;&lt;P&gt;name 192.168.1.2 mail&lt;/P&gt;&lt;P&gt;access-list smtp_in permit tcp any interface outside eq smtp&lt;/P&gt;&lt;P&gt;access-list smtp_in permit tcp any host 59.181.103.222 eq smtp&lt;/P&gt;&lt;P&gt;access-list out_in permit tcp any interface outside eq smtp&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;ip address outside 59.x.x.222 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address inside 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;pdm location mail 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;pdm location adsl 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface smtp mail smtp netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group out_in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 adsl 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-disconnect 0:02:00 sip-invite 0:03:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius&lt;/P&gt;&lt;P&gt;aaa-server RADIUS max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server RADIUS deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http mail 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;Cryptochecksum:xxxx&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you wil get the idea.&lt;/P&gt;&lt;P&gt;Bye&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Mar 2007 12:58:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-cisco-pix-506e-firewall-for-mails-problem/m-p/696288#M1024210</guid>
      <dc:creator>hemanttandel</dc:creator>
      <dc:date>2007-03-10T12:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: configuring cisco pix 506e firewall for mails problem</title>
      <link>https://community.cisco.com/t5/network-security/configuring-cisco-pix-506e-firewall-for-mails-problem/m-p/696289#M1024211</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the conf. is ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The SMTP server is the 59.181.103.222 (the outside interface of the pix !).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.:insert also the following conf. on the pix:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging on&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging monitor warnings&lt;/P&gt;&lt;P&gt;logging buffered warnings&lt;/P&gt;&lt;P&gt;logging trap warnings&lt;/P&gt;&lt;P&gt;no logging console&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Mar 2007 13:45:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-cisco-pix-506e-firewall-for-mails-problem/m-p/696289#M1024211</guid>
      <dc:creator>ROBERTO TACCON</dc:creator>
      <dc:date>2007-03-10T13:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: configuring cisco pix 506e firewall for mails problem</title>
      <link>https://community.cisco.com/t5/network-security/configuring-cisco-pix-506e-firewall-for-mails-problem/m-p/696290#M1024212</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hemant,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I checked the DNS databases and found this-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- loyalindia.co.in is your domain, the MX record for it is mail.loyalindia.co.in which points to 59.181.103.220&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your current configuration on PIX, binds the mail server to use 59.181.103.222 (PIX WAN interface IP) to send outbound mails and recieve mails. That is fine. The reason your outbound mails might be failing is due to reverse-dns lookup. When the destination mail server does a reverse lookup for mail.loyalindia.co.in, it sees 59.181.103.220, however it is recieving the mails from 59.181.103.222 so it rejects the mail giving reverse-lookup failure error. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is what you need to do-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Have the MX record IP changed to 59.181.103.222&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should solve your issues for outbound mails. Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Mar 2007 16:40:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-cisco-pix-506e-firewall-for-mails-problem/m-p/696290#M1024212</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-03-10T16:40:17Z</dc:date>
    </item>
    <item>
      <title>Re: configuring cisco pix 506e firewall for mails problem</title>
      <link>https://community.cisco.com/t5/network-security/configuring-cisco-pix-506e-firewall-for-mails-problem/m-p/696291#M1024213</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But this ip is not live ip 59.181.103.222   &lt;/P&gt;&lt;P&gt;It will work? or i have to purchased the new static ip.&lt;/P&gt;&lt;P&gt;I had also changed my network design with (Purchased) new static ip 59.181.111.159 which was not live and also did not solved my problem. It was not sending and receiving mails.&lt;/P&gt;&lt;P&gt;my design was as fallows:&lt;/P&gt;&lt;P&gt;MX record IP (FQDN) 59.181.111.159&lt;/P&gt;&lt;P&gt;adsl (wan) 59.181.103.220&lt;/P&gt;&lt;P&gt;adsl (lan) 59.181.111.158&lt;/P&gt;&lt;P&gt;pix 506e (out) 59.181.111.159&lt;/P&gt;&lt;P&gt;pix 506e (in) 192.168.1.1&lt;/P&gt;&lt;P&gt;domain mail server (exchange) ip 192.168.1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so what should i do? plz. let me know. waiting for the reply.&lt;/P&gt;&lt;P&gt;Bye.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2007 13:11:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-cisco-pix-506e-firewall-for-mails-problem/m-p/696291#M1024213</guid>
      <dc:creator>hemanttandel</dc:creator>
      <dc:date>2007-03-12T13:11:21Z</dc:date>
    </item>
  </channel>
</rss>

