<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic No problems receving mails, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5525-mailserver-behind-firewall-problem-rdns/m-p/3076274#M147158</link>
    <description>&lt;P&gt;No problems receving mails, only sending mails (they are rejected by other servers)&lt;/P&gt;
&lt;P&gt;Did some test with MX-Tools and the header shows the problem.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Subject: test&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;Received: from fw.domain.dk (HELO fc.domain.dk) ([xx.xx.xx.34]) by mx1.tools.mxtoolbox.com with ESMTP; 06 Feb 2017 09:13:30 -0600&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;Message-id: &amp;lt;fc.00870c7d011bf26700870c7d011bf267.11bf268@domain.dk&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;X-FC-Thread-ID: 00870c7d-011bf267&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;Date: Mon, 06 Feb 2017 16:13:43 +0100&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;X-Mailer: FirstClass 12.1 (build 12.109)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;X-FC-SERVER-TZ: 30147588&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;To: ping@tools.mxtoolbox.com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;From: "xxx" &amp;lt;kvt@domain.dk&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;The HELO is tjecking fc.domain.dk&amp;nbsp; (IP xx.xx.xx.35) and compair it with the fw.domain.dk IP (xx.xx.xx.34) and because the differ in the IP's, mails get rejected.&lt;/P&gt;</description>
    <pubDate>Wed, 08 Feb 2017 21:04:47 GMT</pubDate>
    <dc:creator>kvt000001</dc:creator>
    <dc:date>2017-02-08T21:04:47Z</dc:date>
    <item>
      <title>ASA 5525: Mailserver behind firewall Problem (rDNS)</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-mailserver-behind-firewall-problem-rdns/m-p/3076268#M147137</link>
      <description>&lt;P&gt;Hi All&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;We are using ASA Version 9.4(3) and having an Outbound SMTP problem with our mailserver.&lt;BR /&gt;&lt;BR /&gt;When we send mails the firewall IP is used as sender, not the mailserver IP, and that bounce mails to other mailservers.&lt;BR /&gt;What we want is the mailserver IP to be shown when sending mail, not the firewall IP.&lt;BR /&gt;&lt;BR /&gt;Can someone tell us what we are missing and guide us in the right direction?&lt;BR /&gt;&lt;BR /&gt;Similar problem but with "older" ASA version&lt;BR /&gt;&lt;A href="https://supportforums.cisco.com/discussion/11905686/asa-5505-outbound-smtp-route-problem-rdns" target="_blank"&gt;https://supportforums.cisco.com/discussion/11905686/asa-5505-outbound-smtp-route-problem-rdns&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;The current configuration&lt;BR /&gt;&lt;BR /&gt;External IP Firewall: &amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;xx.xxx.xx.34&lt;BR /&gt;External IP Mailserver:&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;xx.xxx.xx.35&lt;BR /&gt;&lt;BR /&gt;Interfaces:&lt;BR /&gt;&lt;BR /&gt;interface GigabitEthernet0/1 &lt;BR /&gt;nameif INSIDE&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.0.1 255.255.240.0 &lt;BR /&gt;&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt;nameif DMZ&lt;BR /&gt;security-level 50&lt;BR /&gt;ip address 172.16.30.1 255.255.255.0 &lt;BR /&gt;dhcprelay server 192.168.0.254&lt;BR /&gt;&lt;BR /&gt;interface GigabitEthernet0/6&lt;/P&gt;
&lt;P&gt;nameif OUTSIDE&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address xx.xxx.xx.34 255.255.255.224&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Mailserver&lt;BR /&gt;object network host 172.16.30.11&lt;BR /&gt;object network host xx.xxx.xx.35&lt;BR /&gt;&lt;BR /&gt;NAT-Rules&lt;BR /&gt;object network 172.16.30.11&lt;BR /&gt;&amp;nbsp;nat (DMZ,OUTSIDE) static xx.xxx.xx.35&lt;BR /&gt;&lt;BR /&gt;Access-List&lt;BR /&gt;access-list DMZ_in extended permit tcp object 172.16.30.11 any eq smtp&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks for suggestions&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:51:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-mailserver-behind-firewall-problem-rdns/m-p/3076268#M147137</guid>
      <dc:creator>kvt000001</dc:creator>
      <dc:date>2019-03-12T08:51:17Z</dc:date>
    </item>
    <item>
      <title>Have you perhaps got a</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-mailserver-behind-firewall-problem-rdns/m-p/3076269#M147140</link>
      <description>&lt;P&gt;Have you perhaps got a dynamic NAT rule for outbound access before this NAT rule?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2017 23:06:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-mailserver-behind-firewall-problem-rdns/m-p/3076269#M147140</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2017-01-30T23:06:16Z</dc:date>
    </item>
    <item>
      <title>We have those dynamic NAT</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-mailserver-behind-firewall-problem-rdns/m-p/3076270#M147142</link>
      <description>&lt;P&gt;We have those dynamic NAT rule before the static ones&lt;/P&gt;
&lt;P&gt;nat (DMZ,OUTSIDE) source dynamic&amp;nbsp;172.16.30.11 interface service 25 25&lt;BR /&gt;nat INSIDE,OUTSIDE) source dynamic any interface&lt;BR /&gt;nat (DMZ,OUTSIDE) source dynamic any interface&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2017 13:46:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-mailserver-behind-firewall-problem-rdns/m-p/3076270#M147142</guid>
      <dc:creator>kvt000001</dc:creator>
      <dc:date>2017-01-31T13:46:51Z</dc:date>
    </item>
    <item>
      <title>You need to create a full 1</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-mailserver-behind-firewall-problem-rdns/m-p/3076271#M147147</link>
      <description>&lt;P&gt;You need to create a full 1-to-1 NAT to the email server.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;nat (DMZ,OUTSIDE) source static 172.16.30.11 interface&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2017 16:01:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-mailserver-behind-firewall-problem-rdns/m-p/3076271#M147147</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2017-01-31T16:01:09Z</dc:date>
    </item>
    <item>
      <title>I have now following NAT</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-mailserver-behind-firewall-problem-rdns/m-p/3076272#M147153</link>
      <description>&lt;P&gt;I have now following NAT-Rules&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;nat (DMZ,OUTSIDE) source dynamic 172.16.30.11 interface service 25 25&lt;BR /&gt;nat INSIDE,OUTSIDE) source dynamic any interface&lt;BR /&gt;nat (DMZ,OUTSIDE) source dynamic any interface&lt;BR /&gt;nat (DMZ,OUTSIDE) source static 172.16.30.11 interface&lt;BR /&gt;&lt;BR /&gt;NAT-Rules&lt;BR /&gt;object network 172.16.30.11&lt;BR /&gt;&amp;nbsp;nat (DMZ,OUTSIDE) static xx.xxx.xx.35&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is this &lt;SPAN class="match"&gt;sufficient&lt;/SPAN&gt; configuration for the firewall so I can start debugging elsewhere because some is still not right.&lt;/P&gt;
&lt;P&gt;and are some of the rules overkill/dublets and can be removed?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 21:13:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-mailserver-behind-firewall-problem-rdns/m-p/3076272#M147153</guid>
      <dc:creator>kvt000001</dc:creator>
      <dc:date>2017-02-03T21:13:08Z</dc:date>
    </item>
    <item>
      <title>You shouldn't need these. </title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-mailserver-behind-firewall-problem-rdns/m-p/3076273#M147156</link>
      <description>&lt;P&gt;You shouldn't need these.&amp;nbsp; The object NAT should be enough on its own.&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;nat (DMZ,OUTSIDE) source dynamic 172.16.30.11 interface service 25 25&lt;BR /&gt;nat (DMZ,OUTSIDE) source static 172.16.30.11 interface&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You will also need to access-list rule to allow traffic to the object 172.16.30.11 from the outside interface (assuming you want to receive email).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Feb 2017 21:44:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-mailserver-behind-firewall-problem-rdns/m-p/3076273#M147156</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2017-02-03T21:44:57Z</dc:date>
    </item>
    <item>
      <title>No problems receving mails,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-mailserver-behind-firewall-problem-rdns/m-p/3076274#M147158</link>
      <description>&lt;P&gt;No problems receving mails, only sending mails (they are rejected by other servers)&lt;/P&gt;
&lt;P&gt;Did some test with MX-Tools and the header shows the problem.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Subject: test&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;Received: from fw.domain.dk (HELO fc.domain.dk) ([xx.xx.xx.34]) by mx1.tools.mxtoolbox.com with ESMTP; 06 Feb 2017 09:13:30 -0600&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;Message-id: &amp;lt;fc.00870c7d011bf26700870c7d011bf267.11bf268@domain.dk&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;X-FC-Thread-ID: 00870c7d-011bf267&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;Date: Mon, 06 Feb 2017 16:13:43 +0100&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;X-Mailer: FirstClass 12.1 (build 12.109)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;X-FC-SERVER-TZ: 30147588&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;To: ping@tools.mxtoolbox.com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;From: "xxx" &amp;lt;kvt@domain.dk&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;The HELO is tjecking fc.domain.dk&amp;nbsp; (IP xx.xx.xx.35) and compair it with the fw.domain.dk IP (xx.xx.xx.34) and because the differ in the IP's, mails get rejected.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 21:04:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-mailserver-behind-firewall-problem-rdns/m-p/3076274#M147158</guid>
      <dc:creator>kvt000001</dc:creator>
      <dc:date>2017-02-08T21:04:47Z</dc:date>
    </item>
  </channel>
</rss>

