<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco FTD is blocking outlook traffic to Exchange server 2010 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-ftd-is-blocking-outlook-traffic-to-exchange-server-2010/m-p/4634895#M1091072</link>
    <description>&lt;P&gt;Hi Mohammed,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as per your suggestion,&amp;nbsp;&lt;SPAN&gt;system support trace solved the problem by listing missed ports.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks !&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_d236d3a683a05etelesymbol_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-VIP-Advisor lia-component-message-view-widget-author-username"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="certifications-wrapper-message"&gt;
&lt;DIV id="tinyMceEditor_d236d3a683a05etelesymbol_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;
&lt;DIV id="tinyMceEditor_d236d3a683a05etelesymbol_2" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Mon, 20 Jun 2022 11:31:15 GMT</pubDate>
    <dc:creator>telesymbol</dc:creator>
    <dc:date>2022-06-20T11:31:15Z</dc:date>
    <item>
      <title>Cisco FTD is blocking outlook traffic to Exchange server 2010</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-is-blocking-outlook-traffic-to-exchange-server-2010/m-p/4624133#M1090598</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;we've installed two 2130 FTDs in HA, managed with FMCv, we've configured a rule to allow traffic from outlook clients to exchange server 2010 which is installed behind the firewall.&amp;nbsp;below are ports we've included but the outlook shows &lt;STRONG&gt;Disconnected &lt;/STRONG&gt;&amp;amp; can not download email. but when we change the ports to Any, it works and please advise on the issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE width="290"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD rowspan="2" width="290"&gt;443/TCP, 80/TCP, 143/TCP, 993/TCP,110/TCP, 995/TCP, 587/TCP, 25/TCP, 50636/TCP,135/TCP,26602/TCP, 135/TCP, 465, 593, 585&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Fri, 03 Jun 2022 14:30:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-is-blocking-outlook-traffic-to-exchange-server-2010/m-p/4624133#M1090598</guid>
      <dc:creator>telesymbol</dc:creator>
      <dc:date>2022-06-03T14:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD is blocking outlook traffic to Exchange server 2010</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-is-blocking-outlook-traffic-to-exchange-server-2010/m-p/4624147#M1090600</link>
      <description>&lt;P&gt;When the rule is ion place, search the connection events to the Exchange server with Action = Block. That should tell you what else needs to be allowed.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2022 14:46:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-is-blocking-outlook-traffic-to-exchange-server-2010/m-p/4624147#M1090600</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-06-03T14:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD is blocking outlook traffic to Exchange server 2010</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-is-blocking-outlook-traffic-to-exchange-server-2010/m-p/4624437#M1090618</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I also suggest to check MS documents for required ports. There are many&lt;BR /&gt;other ports needed such as endpoint mapper, CAS/HUB, etc.&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Sat, 04 Jun 2022 02:57:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-is-blocking-outlook-traffic-to-exchange-server-2010/m-p/4624437#M1090618</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2022-06-04T02:57:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD is blocking outlook traffic to Exchange server 2010</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-is-blocking-outlook-traffic-to-exchange-server-2010/m-p/4624933#M1090641</link>
      <description>&lt;P&gt;I tried to to search events for traffic from outlook to exchange server 2010, which is behind the firewall but i couldn't found a block action, all are Allowed traffics. is there another way to resolve this issue pls ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jun 2022 20:28:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-is-blocking-outlook-traffic-to-exchange-server-2010/m-p/4624933#M1090641</guid>
      <dc:creator>telesymbol</dc:creator>
      <dc:date>2022-06-04T20:28:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD is blocking outlook traffic to Exchange server 2010</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-is-blocking-outlook-traffic-to-exchange-server-2010/m-p/4624980#M1090649</link>
      <description>Your rule which is blocking might not have logging enabled. From CLISH try&lt;BR /&gt;system support trace (turn in firewall debugs when asked). Use sample&lt;BR /&gt;client IP that you can test from and your server IP. Leave rest of fields&lt;BR /&gt;blank.&lt;BR /&gt;&lt;BR /&gt;Then test and see which rules are matched along with actions.&lt;BR /&gt;&lt;BR /&gt;***** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Sun, 05 Jun 2022 01:07:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-is-blocking-outlook-traffic-to-exchange-server-2010/m-p/4624980#M1090649</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2022-06-05T01:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD is blocking outlook traffic to Exchange server 2010</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-is-blocking-outlook-traffic-to-exchange-server-2010/m-p/4625117#M1090650</link>
      <description>&lt;P&gt;please see attached logs and le me know what is required to allow exchange traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2022 09:25:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-is-blocking-outlook-traffic-to-exchange-server-2010/m-p/4625117#M1090650</guid>
      <dc:creator>telesymbol</dc:creator>
      <dc:date>2022-06-05T09:25:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD is blocking outlook traffic to Exchange server 2010</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-is-blocking-outlook-traffic-to-exchange-server-2010/m-p/4625123#M1090651</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;&amp;gt;From the logs it seems connection is reset from the server (see the rst&lt;BR /&gt;flag in the logs).&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;10.100.20.55-49233 - 10.100.5.74-135 6 AS 1-1 CID 0 Packet: TCP, ACK,&lt;BR /&gt;RST, seq 4003994852, ack 3917801564&lt;BR /&gt;10.100.20.55-49233 - 10.100.5.74-135 6 AS 1-1 CID 0 AppID: service&lt;BR /&gt;DCE/RPC (603), application unknown (0)&lt;BR /&gt;10.100.20.55-49233 - 10.100.5.74-135 6 AS 1-1 CID 0 Firewall: allow&lt;BR /&gt;rule, 'EIC_MS-Exchange_Access', allow&lt;BR /&gt;10.100.20.55-49233 - 10.100.5.74-135 6 AS 1-1 CID 0 Snort id 4, NAP id&lt;BR /&gt;2, IPS id 0, Verdict PASS&lt;BR /&gt;10.100.20.55-49233 &amp;gt; 10.100.5.74-135 6 AS 1-1 I 4 Got end of flow&lt;BR /&gt;event from hardware with flags 00010001. Rule Match Data: rule_id 0,&lt;BR /&gt;rule_action 0 rev_id 0, rule_flags 2&lt;BR /&gt;10.100.20.55-49233 &amp;gt; 10.100.5.74-135 6 AS 1-1 I 4 Logging EOF for&lt;BR /&gt;event from hardware with rule_id = 268437546 ruleAction = 2 ruleReason&lt;BR /&gt;= 0&lt;BR /&gt;10.100.20.55-49233 &amp;gt; 10.100.5.74-135 6 AS 1-1 I 4 : Received EOF,&lt;BR /&gt;deleting the snort session&lt;BR /&gt;&lt;BR /&gt;Check your server. If you have esmtp inspection enables, try to disable it&lt;BR /&gt;and check.&lt;BR /&gt;&lt;BR /&gt;***** please remember to rate useful posts&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sun, 05 Jun 2022 09:53:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-is-blocking-outlook-traffic-to-exchange-server-2010/m-p/4625123#M1090651</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2022-06-05T09:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD is blocking outlook traffic to Exchange server 2010</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-is-blocking-outlook-traffic-to-exchange-server-2010/m-p/4625189#M1090658</link>
      <description>&lt;P&gt;I've disabled ESMTP inspection but still outlook can not connect to exchange server 2010. here attached is the new log from the FTD.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2022 14:33:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-is-blocking-outlook-traffic-to-exchange-server-2010/m-p/4625189#M1090658</guid>
      <dc:creator>telesymbol</dc:creator>
      <dc:date>2022-06-05T14:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD is blocking outlook traffic to Exchange server 2010</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-is-blocking-outlook-traffic-to-exchange-server-2010/m-p/4625239#M1090659</link>
      <description>This is better trace. As suspected, there are missing ports from your ACP&lt;BR /&gt;which are not allowed and falling in default action. Sample below.&lt;BR /&gt;&lt;BR /&gt;Review  MS documentation to ensure all required ports are allowed.&lt;BR /&gt;&lt;BR /&gt;10.100.20.55-53796 &amp;gt; 10.100.5.74-62003 6 AS 1-1 I 5 match rule order&lt;BR /&gt;52, 'Default Action', action Block&lt;BR /&gt;10.100.20.55-53796 &amp;gt; 10.100.5.74-62003 6 AS 1-1 I 5 MidRecovery data&lt;BR /&gt;sent for rule id: 268435577,rule_action:4, rev id:1052613730,&lt;BR /&gt;rule_match flag:0x0&lt;BR /&gt;10.100.20.55-53796 &amp;gt; 10.100.5.74-62003 6 AS 1-1 I 5 HitCount data sent&lt;BR /&gt;for rule id: 268435577,&lt;BR /&gt;10.100.20.55-53796 &amp;gt; 10.100.5.74-62003 6 AS 1-1 I 5 deny action&lt;BR /&gt;10.100.20.55-53796 - 10.100.5.74-62003 6 AS 1-1 CID 0 Firewall: block&lt;BR /&gt;rule, 'Default Action', drop&lt;BR /&gt;10.100.20.55-53796 - 10.100.5.74-62003 6 AS 1-1 CID 0 Snort: processed&lt;BR /&gt;decoder alerts or actions queue, drop&lt;BR /&gt;10.100.20.55-53796 &amp;gt; 10.100.5.74-62003 6 AS 1-1 I 5 Deleting session&lt;BR /&gt;10.100.20.55-53796 &amp;gt; 10.100.5.74-62003 6 AS 1-1 I 5 deleting firewall&lt;BR /&gt;session flags = 0x0, fwFlags = 0x1000, session-&amp;gt;logFlags = 0ec4008c0&lt;BR /&gt;10.100.20.55-53796 - 10.100.5.74-62003 6 AS 1-1 CID 0 Snort id 5, NAP&lt;BR /&gt;id 2, IPS id 0, Verdict BLACKLIST&lt;BR /&gt;10.100.20.55-53796 - 10.100.5.74-62003 6 AS 1-1 CID 0 ===&amp;gt; Blocked by Firewall&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sun, 05 Jun 2022 16:39:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-is-blocking-outlook-traffic-to-exchange-server-2010/m-p/4625239#M1090659</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2022-06-05T16:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD is blocking outlook traffic to Exchange server 2010</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-is-blocking-outlook-traffic-to-exchange-server-2010/m-p/4634895#M1091072</link>
      <description>&lt;P&gt;Hi Mohammed,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as per your suggestion,&amp;nbsp;&lt;SPAN&gt;system support trace solved the problem by listing missed ports.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks !&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_d236d3a683a05etelesymbol_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-VIP-Advisor lia-component-message-view-widget-author-username"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="certifications-wrapper-message"&gt;
&lt;DIV id="tinyMceEditor_d236d3a683a05etelesymbol_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;
&lt;DIV id="tinyMceEditor_d236d3a683a05etelesymbol_2" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 20 Jun 2022 11:31:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-is-blocking-outlook-traffic-to-exchange-server-2010/m-p/4634895#M1091072</guid>
      <dc:creator>telesymbol</dc:creator>
      <dc:date>2022-06-20T11:31:15Z</dc:date>
    </item>
  </channel>
</rss>

