<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inspect ESMTP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663478#M1024723</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I discovered the problem at the beginning of january because our e-mail servers could not receive a lot of messages. I understood that it was related to the upgrade of PIX OS from 7.1.x (yes, in 7.1.x ESMTP inspection works, but is less accurate than in 7.2.x) to 7.2.2.&lt;/P&gt;&lt;P&gt;It's not true that I have a deep understanding of SMTP protocol. I debugged PIX behaviour with the help of a Cisco engineer, I analyzed blocked messages, then I studied a lot of RFCs (but I understood only what I needed to understand the problem).&lt;/P&gt;&lt;P&gt;I hope that my message could help you. I hope that the TAC cases I have opened help Cisco fix this 7.2.x OS that I believe is too much buggy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Mar 2007 14:41:31 GMT</pubDate>
    <dc:creator>oxys</dc:creator>
    <dc:date>2007-03-07T14:41:31Z</dc:date>
    <item>
      <title>Inspect ESMTP</title>
      <link>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663467#M1024693</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How you explain that we you apply in configuration command inspect esmtp with pix version 7(2)1, there is some trouble with mail. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm using exchange server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you a lot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:38:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663467#M1024693</guid>
      <dc:creator>fargier</dc:creator>
      <dc:date>2019-03-11T09:38:56Z</dc:date>
    </item>
    <item>
      <title>Re: Inspect ESMTP</title>
      <link>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663468#M1024694</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;because that is a "known" issue since version&lt;/P&gt;&lt;P&gt;6.x.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Feb 2007 14:28:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663468#M1024694</guid>
      <dc:creator>daviddtran</dc:creator>
      <dc:date>2007-02-27T14:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: Inspect ESMTP</title>
      <link>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663469#M1024697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believed that this problem was corrected with pix version 7. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Feb 2007 14:46:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663469#M1024697</guid>
      <dc:creator>fargier</dc:creator>
      <dc:date>2007-02-27T14:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: Inspect ESMTP</title>
      <link>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663470#M1024699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am running version 7.2(2) and my exchange&lt;/P&gt;&lt;P&gt;server is win2k3 w/ service pack 1 behind the&lt;/P&gt;&lt;P&gt;firewall and I am having intermittent issue&lt;/P&gt;&lt;P&gt;with mail until I do "no fixup protcol smpt 25"&lt;/P&gt;&lt;P&gt;and the issue goes away.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Feb 2007 14:49:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663470#M1024699</guid>
      <dc:creator>daviddtran</dc:creator>
      <dc:date>2007-02-27T14:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: Inspect ESMTP</title>
      <link>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663471#M1024703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have done the same to correct this problem. But i would like to know why ?? Some smtp doesn't respect RFC ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Feb 2007 15:05:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663471#M1024703</guid>
      <dc:creator>fargier</dc:creator>
      <dc:date>2007-02-27T15:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: Inspect ESMTP</title>
      <link>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663472#M1024704</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi all in the new ios. pix or ur asa can inspect EMSTP traffic to check for RFC compliance. now ur windows smtp or exchange server doesn;t use basic smtp commands it uses extended smtp commands called as ESMTP. for mail to work properly across firewall with rfc valid commands. set the inspect to ESMTP. i am sure this inspection is there by default. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sebastan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Feb 2007 15:38:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663472#M1024704</guid>
      <dc:creator>sebastan_bach</dc:creator>
      <dc:date>2007-02-27T15:38:51Z</dc:date>
    </item>
    <item>
      <title>Re: Inspect ESMTP</title>
      <link>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663473#M1024709</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i've found that:&lt;/P&gt;&lt;P&gt;CSCsg52277&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm in 7.2(1) Probably corrected in 7.2(2)..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Feb 2007 15:40:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663473#M1024709</guid>
      <dc:creator>fargier</dc:creator>
      <dc:date>2007-02-27T15:40:18Z</dc:date>
    </item>
    <item>
      <title>Re: Inspect ESMTP</title>
      <link>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663474#M1024710</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"I am running version 7.2(2) and my exchange &lt;/P&gt;&lt;P&gt;server is win2k3 w/ service pack 1 behind the &lt;/P&gt;&lt;P&gt;firewall and I am having intermittent issue &lt;/P&gt;&lt;P&gt;with mail until I do "no fixup protcol smpt 25" &lt;/P&gt;&lt;P&gt;and the issue goes away. "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in 7.2.2,there's no command as fixup".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have inspect commands in 7.x&lt;/P&gt;&lt;P&gt;please correct.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Mar 2007 18:38:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663474#M1024710</guid>
      <dc:creator>suschoud</dc:creator>
      <dc:date>2007-03-05T18:38:57Z</dc:date>
    </item>
    <item>
      <title>Re: Inspect ESMTP</title>
      <link>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663475#M1024713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In 7.2.x (including the latest 7.2.2 interim releases) there are bugs related to SMTP/ESMTP inspection. PIX inspection engine drops connections if it finds a registered header name, as "Content-type", inside another header of any kind. This can happen if you use SpamAssassin and configure it to save reports inside e-mail header, or a remarkable case is Gmail which uses control headers containing other header names as keywords. &lt;/P&gt;&lt;P&gt;The problem is that RFCs do not forbid the use of a header name inside another header, but PIX/ASA Os 7.2.x incorrectly detects this behaviour as "malicious" because it sees a duplicate header. So it's the PIX that is wrong, not the messages. I opened a TAC case for this bug about one month ago.&lt;/P&gt;&lt;P&gt;The bug is now recognized as CSCsh33982, a level 2 bug. If you look in the Bug Toolkit you'll find the bug and you'll see that it is fixed in version 7.2(2)12 and 8.x. OS 7.2(2)12 is an interim release, but it is not public. Actually, today I installed it and I have found that the bug is not fully fixed: sometimes Gmail inserts two headers with the same keywords inside a message and the ASA/PIX still drops these messages. A new bug has been recognized: CSCsi01498. &lt;/P&gt;&lt;P&gt;So, at the moment, the only correct suggestion I can give you is to disable SMTP/EMSTP inspection if you use PIX/ASA OS 7.2.x. At least remove it for the traffic originated by or directed to your mail server if you don't want to loose messages. &lt;/P&gt;&lt;P&gt;Another note: serious modern e-mail servers allow you to configure security features for their SMTP service comparable or even better than those provided by PIX inspection. Even MS Exchange can be configured properly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Mar 2007 14:22:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663475#M1024713</guid>
      <dc:creator>oxys</dc:creator>
      <dc:date>2007-03-07T14:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: Inspect ESMTP</title>
      <link>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663476#M1024717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great answer ! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Mar 2007 14:25:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663476#M1024717</guid>
      <dc:creator>fargier</dc:creator>
      <dc:date>2007-03-07T14:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: Inspect ESMTP</title>
      <link>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663477#M1024720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi man u have a great and a detailed understanding of the smtp protocol man not even ccie;s out here know the inner working of things like this. keep it up and keeps us updated on stuff like this. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;just curious to know how did u find out this was the problem. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sebastan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Mar 2007 14:28:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663477#M1024720</guid>
      <dc:creator>sebastan_bach</dc:creator>
      <dc:date>2007-03-07T14:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: Inspect ESMTP</title>
      <link>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663478#M1024723</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I discovered the problem at the beginning of january because our e-mail servers could not receive a lot of messages. I understood that it was related to the upgrade of PIX OS from 7.1.x (yes, in 7.1.x ESMTP inspection works, but is less accurate than in 7.2.x) to 7.2.2.&lt;/P&gt;&lt;P&gt;It's not true that I have a deep understanding of SMTP protocol. I debugged PIX behaviour with the help of a Cisco engineer, I analyzed blocked messages, then I studied a lot of RFCs (but I understood only what I needed to understand the problem).&lt;/P&gt;&lt;P&gt;I hope that my message could help you. I hope that the TAC cases I have opened help Cisco fix this 7.2.x OS that I believe is too much buggy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Mar 2007 14:41:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663478#M1024723</guid>
      <dc:creator>oxys</dc:creator>
      <dc:date>2007-03-07T14:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: Inspect ESMTP</title>
      <link>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663479#M1024724</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi buddy thanks a lot for ur reply. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i guess but the 7.2.2 code was just of bug fixes and suggested by cisco as the stable version. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sebastan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Mar 2007 14:43:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspect-esmtp/m-p/663479#M1024724</guid>
      <dc:creator>sebastan_bach</dc:creator>
      <dc:date>2007-03-07T14:43:49Z</dc:date>
    </item>
  </channel>
</rss>

