<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SMTP telnet obscured Banner 220 **** ESMTP - no inspect ESMPT and Fixup not working in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/smtp-telnet-obscured-banner-220-esmtp-no-inspect-esmpt-and-fixup/m-p/3222437#M14755</link>
    <description>Thanks Flavio, I think it is the Firewall. On the local LAN I can telnet on smtp 25 onto their mail server and get the banner.  Only from outside Public internet I hit the problem. Thanks for your input. Another set of eyes on it is helpful.&lt;BR /&gt;&lt;BR /&gt;Has anyone else got an insight as to what could be the cause&lt;BR /&gt;&lt;BR /&gt;Dave&lt;BR /&gt;</description>
    <pubDate>Sat, 25 Nov 2017 17:02:16 GMT</pubDate>
    <dc:creator>davidfield</dc:creator>
    <dc:date>2017-11-25T17:02:16Z</dc:date>
    <item>
      <title>SMTP telnet obscured Banner 220 **** ESMTP - no inspect ESMPT and Fixup not working</title>
      <link>https://community.cisco.com/t5/network-security/smtp-telnet-obscured-banner-220-esmtp-no-inspect-esmpt-and-fixup/m-p/3222254#M14750</link>
      <description>&lt;P&gt;Content Removed&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:49:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/smtp-telnet-obscured-banner-220-esmtp-no-inspect-esmpt-and-fixup/m-p/3222254#M14750</guid>
      <dc:creator>davidfield</dc:creator>
      <dc:date>2020-02-21T14:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: SMTP telnet obscured Banner 220 **** ESMTP - no inspect ESMPT and Fixup not working</title>
      <link>https://community.cisco.com/t5/network-security/smtp-telnet-obscured-banner-220-esmtp-no-inspect-esmpt-and-fixup/m-p/3222263#M14751</link>
      <description>&lt;P&gt;I've tried to apply a PolicyMap/Class Map for the Mailserver source IP address to not match ESMTP for the internal IP 192.168.150.3 .&amp;nbsp; No change.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access-list ESMTP deny ip host 192.168.150.3 any&lt;BR /&gt;access-list ESMTP permit ip 192.168.150.0 255.255.255.0 any&lt;/P&gt;
&lt;P&gt;class-map CMAP&lt;BR /&gt;match access-list ESMTP&lt;/P&gt;
&lt;P&gt;policy-map PMAP&lt;BR /&gt;class CMAP&lt;BR /&gt;inspect esmtp&lt;/P&gt;
&lt;P&gt;service-policy PMAP interface inside&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 21:50:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/smtp-telnet-obscured-banner-220-esmtp-no-inspect-esmpt-and-fixup/m-p/3222263#M14751</guid>
      <dc:creator>davidfield</dc:creator>
      <dc:date>2017-11-24T21:50:42Z</dc:date>
    </item>
    <item>
      <title>Re: SMTP telnet obscured Banner 220 **** ESMTP - no inspect ESMPT and Fixup not working</title>
      <link>https://community.cisco.com/t5/network-security/smtp-telnet-obscured-banner-220-esmtp-no-inspect-esmpt-and-fixup/m-p/3222267#M14752</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/321940"&gt;@davidfield&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;Sorry if I miss something. I understood that you are trying hard disable inspect for smtp but what is your problem? I assume that smtp service is not working but can you give more information about the environment and the problem?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 21:59:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/smtp-telnet-obscured-banner-220-esmtp-no-inspect-esmpt-and-fixup/m-p/3222267#M14752</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2017-11-24T21:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: SMTP telnet obscured Banner 220 **** ESMTP - no inspect ESMPT and Fixup not working</title>
      <link>https://community.cisco.com/t5/network-security/smtp-telnet-obscured-banner-220-esmtp-no-inspect-esmpt-and-fixup/m-p/3222270#M14753</link>
      <description>&lt;P&gt;Hi Flavio,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SMTP traffic is passing to the Server but the ASA is interfering with the contents.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't manage the Mailserver and this being a new Firewall and Exchange server the Server guys are refusing to accept the network Firewall config as Operational for handover&amp;nbsp;until they see the banner.&amp;nbsp; I've advised them that the inspection just restricts less used&amp;nbsp;commands and the banner from being read but they will not have it.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;What we see at the moment when telneting to IP on port 25&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;telnet&amp;nbsp;59.147.41.134 25&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- not the real IP addr&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;220 ************************************************************&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;500 5.3.3 Unrecognized command&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;500 5.3.3 Unrecognized command&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 22:06:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/smtp-telnet-obscured-banner-220-esmtp-no-inspect-esmpt-and-fixup/m-p/3222270#M14753</guid>
      <dc:creator>davidfield</dc:creator>
      <dc:date>2017-11-24T22:06:37Z</dc:date>
    </item>
    <item>
      <title>Re: SMTP telnet obscured Banner 220 **** ESMTP - no inspect ESMPT and Fixup not working</title>
      <link>https://community.cisco.com/t5/network-security/smtp-telnet-obscured-banner-220-esmtp-no-inspect-esmpt-and-fixup/m-p/3222274#M14754</link>
      <description>&lt;P&gt;I am not exchange expert by no means but I think you did your job with firewall so maybe is time to think in something else.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;For example, looking at Microsoft docs, I read this:&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="text-base"&gt;Numeric Code:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;5.3.3&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class="text-base"&gt;Possible Cause:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;The Exchange 2000 remote server or the Exchange 2003 remote server is out of disk storage to hold mail. This problem occurs most frequently when the sending server sends mail that includes binary DATA (BDAT). This code may also indicate an SMTP protocol error.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 22:15:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/smtp-telnet-obscured-banner-220-esmtp-no-inspect-esmpt-and-fixup/m-p/3222274#M14754</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2017-11-24T22:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: SMTP telnet obscured Banner 220 **** ESMTP - no inspect ESMPT and Fixup not working</title>
      <link>https://community.cisco.com/t5/network-security/smtp-telnet-obscured-banner-220-esmtp-no-inspect-esmpt-and-fixup/m-p/3222437#M14755</link>
      <description>Thanks Flavio, I think it is the Firewall. On the local LAN I can telnet on smtp 25 onto their mail server and get the banner.  Only from outside Public internet I hit the problem. Thanks for your input. Another set of eyes on it is helpful.&lt;BR /&gt;&lt;BR /&gt;Has anyone else got an insight as to what could be the cause&lt;BR /&gt;&lt;BR /&gt;Dave&lt;BR /&gt;</description>
      <pubDate>Sat, 25 Nov 2017 17:02:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/smtp-telnet-obscured-banner-220-esmtp-no-inspect-esmpt-and-fixup/m-p/3222437#M14755</guid>
      <dc:creator>davidfield</dc:creator>
      <dc:date>2017-11-25T17:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: SMTP telnet obscured Banner 220 **** ESMTP - no inspect ESMPT and Fixup not working</title>
      <link>https://community.cisco.com/t5/network-security/smtp-telnet-obscured-banner-220-esmtp-no-inspect-esmpt-and-fixup/m-p/3908385#M14756</link>
      <description>&lt;P&gt;I had this exact same problem, and when I REMOVED the "fixup protocol smtp 25" parameter, it fixed the issue.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 21:57:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/smtp-telnet-obscured-banner-220-esmtp-no-inspect-esmpt-and-fixup/m-p/3908385#M14756</guid>
      <dc:creator>beatinger</dc:creator>
      <dc:date>2019-08-14T21:57:04Z</dc:date>
    </item>
  </channel>
</rss>

