<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Two Exchange servers at same network could not send email to in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/two-exchange-servers-at-same-network-could-not-send-email-to/m-p/609605#M1032125</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I couldn't say more without looking at your configuration, but I'd start out with a &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will allow traffic to go in/out the same interface.  This might help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate this message if it solved some or all of your issue/question.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 16 Dec 2006 21:45:02 GMT</pubDate>
    <dc:creator>jgervia_2</dc:creator>
    <dc:date>2006-12-16T21:45:02Z</dc:date>
    <item>
      <title>Two Exchange servers at same network could not send email to each other</title>
      <link>https://community.cisco.com/t5/network-security/two-exchange-servers-at-same-network-could-not-send-email-to/m-p/609604#M1032124</link>
      <description>&lt;P&gt;This is my scenario.&lt;/P&gt;&lt;P&gt;#1 One PIX 515 has three interfaces:Outside, Inside and DMZ1&lt;/P&gt;&lt;P&gt;#2. Two Exchange servers in the Inside interface. Server#1 10.0.1.10 hosts abc.com , Server #2 10.0.86.20 hosts xyz.com&lt;/P&gt;&lt;P&gt;#3. Two Symantec SMTP mail gateway server on DMZ1 interface: SMTP gateway1 - 172.16.1.10, SMTP Gateway2 - 172.16.1.20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#4. SMTP Gateway1 forward both inbound and outbound mail for Exchange server 1&lt;/P&gt;&lt;P&gt;    SMTP Gateway2 forward both inbound and outbound mail for Exchange server 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#5. There are Static NAT for one public IP to each SMTP gateways:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz1, outside) 200.211.10.10 172.16.1.10 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz1, outside) 200.211.10.20 172.16.1.20 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and inculde ACL to permit both inbound and outbound SMTP port 25&lt;/P&gt;&lt;P&gt;#6. MX record for abc.com is 200.211.10.10&lt;/P&gt;&lt;P&gt;MX record for xyz.com is 200.211.10.20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#7. Both Exchange servers could send and receive Internet emails from outside Mail servers, but could not send email between abc.com and xyz.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#8.Have tried to use alias command for DNS doctoring, and did not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that the PIX outside interface, the both public addresses could not pass traffic to each other. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any configure could be done to allow 200.211.10.10 and 200.211.10.20 to send smtp traffic to each other?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance &lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:09:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-exchange-servers-at-same-network-could-not-send-email-to/m-p/609604#M1032124</guid>
      <dc:creator>rawsonfang</dc:creator>
      <dc:date>2019-03-11T09:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: Two Exchange servers at same network could not send email to</title>
      <link>https://community.cisco.com/t5/network-security/two-exchange-servers-at-same-network-could-not-send-email-to/m-p/609605#M1032125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I couldn't say more without looking at your configuration, but I'd start out with a &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will allow traffic to go in/out the same interface.  This might help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate this message if it solved some or all of your issue/question.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Dec 2006 21:45:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-exchange-servers-at-same-network-could-not-send-email-to/m-p/609605#M1032125</guid>
      <dc:creator>jgervia_2</dc:creator>
      <dc:date>2006-12-16T21:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: Two Exchange servers at same network could not send email to</title>
      <link>https://community.cisco.com/t5/network-security/two-exchange-servers-at-same-network-could-not-send-email-to/m-p/609606#M1032126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What MX your exchange servers resolves internally?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ping mx.abc.com from exchange.xyz.com&lt;/P&gt;&lt;P&gt;ping mx.xyz.com from exchange.abc.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Muhammad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Dec 2006 03:00:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-exchange-servers-at-same-network-could-not-send-email-to/m-p/609606#M1032126</guid>
      <dc:creator>msubtain</dc:creator>
      <dc:date>2006-12-18T03:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: Two Exchange servers at same network could not send email to</title>
      <link>https://community.cisco.com/t5/network-security/two-exchange-servers-at-same-network-could-not-send-email-to/m-p/609607#M1032127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From exchange.abc.com, the MX for the mx.abc.com is 200.211.10.10 and&lt;/P&gt;&lt;P&gt;From exchange.xyz.com, the MX for the mx.xyz.com is 200.211.10.20 &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Dec 2006 14:56:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-exchange-servers-at-same-network-could-not-send-email-to/m-p/609607#M1032127</guid>
      <dc:creator>rawsonfang</dc:creator>
      <dc:date>2006-12-18T14:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: Two Exchange servers at same network could not send email to</title>
      <link>https://community.cisco.com/t5/network-security/two-exchange-servers-at-same-network-could-not-send-email-to/m-p/609608#M1032128</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;DNS Doctoring should sovle your problem:&lt;/P&gt;&lt;P&gt;1. check your alias command, they should be&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;alias (dmz1) 172.16.1.10 200.211.10.10 255.255.255.255&lt;/P&gt;&lt;P&gt;alias (dmz1) 172.16.1.20 200.211.10.20 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. or your can configure your static with "dns" argument&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz1, outside) 200.211.10.10 172.16.1.10 255.255.255.255 dns&lt;/P&gt;&lt;P&gt;static (dmz1, outside) 200.211.10.20 172.16.1.20 255.255.255.255 dns&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. or modify both exchange server HOST file&lt;/P&gt;&lt;P&gt;mx.abc.com 172.16.1.10&lt;/P&gt;&lt;P&gt;mx.xyz.com 172.16.1.20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In exchange server mx.abc.com ping mx.xyz.com,it should resolved as 172.16.1.20.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if the post help,please rate, thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;peng&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Dec 2006 19:58:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-exchange-servers-at-same-network-could-not-send-email-to/m-p/609608#M1032128</guid>
      <dc:creator>pengfang</dc:creator>
      <dc:date>2006-12-21T19:58:30Z</dc:date>
    </item>
  </channel>
</rss>

