<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic This is just like a Cisco in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/multiple-multiple-emails-with-no-esmtp-inspection/m-p/2807781#M172775</link>
    <description>&lt;P&gt;This is just like a Cisco router for Cisco firewall doing (E)SMTP inspection.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you post your firewall config? &amp;nbsp;Do you have any routers running IOS firewall? &amp;nbsp;If so, can you post their config please.&lt;/P&gt;</description>
    <pubDate>Tue, 09 Feb 2016 18:16:36 GMT</pubDate>
    <dc:creator>Philip D'Ath</dc:creator>
    <dc:date>2016-02-09T18:16:36Z</dc:date>
    <item>
      <title>Multiple multiple emails with no esmtp inspection</title>
      <link>https://community.cisco.com/t5/network-security/multiple-multiple-emails-with-no-esmtp-inspection/m-p/2807778#M172770</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;I'm running into an issue where we are receiving multiple duplicates of emails (E-Mail volume increasing 10 fold) in our domain. Working with our filtering provider they are saying it is an issue with esmtp inspection / fixup smtp settings on our ASA since the SMTP server login banner is being replaced by all *'s.&lt;/P&gt;
&lt;P&gt;I've gone through the ASA config multiple times and made sure we are not inspecting any SMTP protocols and have not seen the problem. When telnetting to our filtering device from the internal interface I receive the banner as expected. I'm wondering if anyone has seen this issue and if there are any tips on what to check out. This has only recently started and we have not made any changes with our firewall config, so it is rather puzzling.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for any input that you can provide!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:15:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-multiple-emails-with-no-esmtp-inspection/m-p/2807778#M172770</guid>
      <dc:creator>rsaeks</dc:creator>
      <dc:date>2019-03-12T07:15:24Z</dc:date>
    </item>
    <item>
      <title>If you can telnet to their</title>
      <link>https://community.cisco.com/t5/network-security/multiple-multiple-emails-with-no-esmtp-inspection/m-p/2807779#M172772</link>
      <description>&lt;P&gt;If you can telnet to their server on port 25 and see a plain banner than it is not likely to be SMTP inspection.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Ask them to send a screenshot of what they see.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you post just your service policies so we can confirm SMTP inspection is off?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 00:16:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-multiple-emails-with-no-esmtp-inspection/m-p/2807779#M172772</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-02-09T00:16:21Z</dc:date>
    </item>
    <item>
      <title>The output of show service</title>
      <link>https://community.cisco.com/t5/network-security/multiple-multiple-emails-with-no-esmtp-inspection/m-p/2807780#M172773</link>
      <description>&lt;P&gt;The&amp;nbsp;output of show service-policy is blank and&lt;/P&gt;
&lt;P&gt;The banner displayed is: 220&amp;nbsp;*****************************************************&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We are also working along with our ISP to see if there is anything they can help with. It's a bizarre one!&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 16:27:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-multiple-emails-with-no-esmtp-inspection/m-p/2807780#M172773</guid>
      <dc:creator>rsaeks</dc:creator>
      <dc:date>2016-02-09T16:27:13Z</dc:date>
    </item>
    <item>
      <title>This is just like a Cisco</title>
      <link>https://community.cisco.com/t5/network-security/multiple-multiple-emails-with-no-esmtp-inspection/m-p/2807781#M172775</link>
      <description>&lt;P&gt;This is just like a Cisco router for Cisco firewall doing (E)SMTP inspection.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you post your firewall config? &amp;nbsp;Do you have any routers running IOS firewall? &amp;nbsp;If so, can you post their config please.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 18:16:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-multiple-emails-with-no-esmtp-inspection/m-p/2807781#M172775</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-02-09T18:16:36Z</dc:date>
    </item>
    <item>
      <title>Below is the cleaned up</title>
      <link>https://community.cisco.com/t5/network-security/multiple-multiple-emails-with-no-esmtp-inspection/m-p/2807782#M172777</link>
      <description>&lt;P&gt;Below is the cleaned up output from our ASA. We do have a router but it is not running an IOS firewall.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ASA:&lt;/P&gt;
&lt;P&gt;hostname GCS-FW-INTERNET&lt;BR /&gt;name 192.168.48.55 GSSPRES01&lt;BR /&gt;name X.X.X.X Security_Monitoring&lt;BR /&gt;name 192.168.41.7 SouthOffice description SouthOffice&lt;BR /&gt;name 17.0.0.0 AppleAPNS&lt;BR /&gt;dns-guard&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt;&amp;nbsp;speed 100&lt;BR /&gt;&amp;nbsp;duplex full&lt;BR /&gt;&amp;nbsp;nameif outside&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address X.X.X.X 255.255.255.240 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;&amp;nbsp;nameif inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 172.20.1.2 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;&amp;nbsp;speed 100&lt;BR /&gt;&amp;nbsp;duplex full&lt;BR /&gt;&amp;nbsp;nameif dmz&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 10.1.1.1 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;&amp;nbsp;nameif guest_inet&lt;BR /&gt;&amp;nbsp;security-level 10&lt;BR /&gt;&amp;nbsp;ip address 10.2.1.1 255.255.254.0 &lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;nameif management&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;&amp;nbsp;management-only&lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa825-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone CST -6&lt;BR /&gt;clock summer-time CDT recurring&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;&amp;nbsp;domain-name glencoeschools.org&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object-group service glenmanage tcp&lt;BR /&gt;&amp;nbsp;port-object eq ftp&lt;BR /&gt;&amp;nbsp;port-object eq ftp-data&lt;BR /&gt;&amp;nbsp;port-object eq ssh&lt;BR /&gt;&amp;nbsp;port-object eq 311&lt;BR /&gt;&amp;nbsp;port-object eq 331&lt;BR /&gt;&amp;nbsp;port-object eq 548&lt;BR /&gt;&amp;nbsp;port-object eq 660&lt;BR /&gt;&amp;nbsp;port-object eq 687&lt;BR /&gt;&amp;nbsp;port-object eq 10000&lt;BR /&gt;object-group service mdaemon tcp&lt;BR /&gt;&amp;nbsp;port-object eq smtp&lt;BR /&gt;&amp;nbsp;port-object eq pop3&lt;BR /&gt;&amp;nbsp;port-object eq imap4&lt;BR /&gt;&amp;nbsp;port-object eq ident&lt;BR /&gt;&amp;nbsp;port-object eq https&lt;BR /&gt;&amp;nbsp;port-object eq 465&lt;BR /&gt;&amp;nbsp;port-object eq 587&lt;BR /&gt;&amp;nbsp;port-object eq 7071&lt;BR /&gt;&amp;nbsp;port-object eq 993&lt;BR /&gt;object-group service schooldude tcp&lt;BR /&gt;&amp;nbsp;port-object eq www&lt;BR /&gt;&amp;nbsp;port-object eq 3011&lt;BR /&gt;&amp;nbsp;port-object eq 1911&lt;BR /&gt;object-group network sipsource&lt;BR /&gt;&amp;nbsp;network-object X.X.X.X 255.255.255.255&lt;BR /&gt;object-group network SIP-Interface&lt;BR /&gt;&amp;nbsp;network-object X.X.X.X 255.255.255.255&lt;BR /&gt;object-group service jabber tcp&lt;BR /&gt;&amp;nbsp;description 8443&lt;BR /&gt;&amp;nbsp;port-object eq 8443&lt;BR /&gt;object-group network gws-sip&lt;BR /&gt;&amp;nbsp;network-object host X.X.X.X&lt;BR /&gt;object-group network Block-IP-Ranges&lt;BR /&gt;&amp;nbsp;network-object 105.220.0.0 255.255.0.0&lt;BR /&gt;&amp;nbsp;network-object 105.221.0.0 255.255.0.0&lt;BR /&gt;&amp;nbsp;network-object 105.222.0.0 255.255.0.0&lt;BR /&gt;&amp;nbsp;network-object 105.223.0.0 255.255.0.0&lt;BR /&gt;&amp;nbsp;network-object 105.224.0.0 255.255.0.0&lt;BR /&gt;&amp;nbsp;network-object 105.225.0.0 255.255.0.0&lt;BR /&gt;&amp;nbsp;network-object 105.226.0.0 255.255.0.0&lt;BR /&gt;&amp;nbsp;network-object 105.227.0.0 255.255.0.0&lt;BR /&gt;&amp;nbsp;network-object 105.228.0.0 255.255.0.0&lt;BR /&gt;&amp;nbsp;network-object 105.229.0.0 255.255.0.0&lt;BR /&gt;object-group network securityCameras&lt;BR /&gt;&amp;nbsp;network-object host 192.168.42.3&lt;BR /&gt;&amp;nbsp;network-object host 192.168.57.3&lt;BR /&gt;&amp;nbsp;network-object host 192.168.51.7&lt;BR /&gt;object-group service SecurityCameras&lt;BR /&gt;&amp;nbsp;description Security Camera Ports&lt;BR /&gt;&amp;nbsp;service-object tcp eq ftp &lt;BR /&gt;&amp;nbsp;service-object tcp eq www &lt;BR /&gt;&amp;nbsp;service-object udp eq ntp &lt;BR /&gt;object-group service APNS tcp&lt;BR /&gt;&amp;nbsp;description Apple Push Notifications&lt;BR /&gt;&amp;nbsp;port-object eq 2195&lt;BR /&gt;&amp;nbsp;port-object eq 2196&lt;BR /&gt;&amp;nbsp;port-object eq 5223&lt;BR /&gt;&amp;nbsp;port-object eq https&lt;BR /&gt;object-group service DM_INLINE_TCP_1 tcp&lt;BR /&gt;&amp;nbsp;port-object eq https&lt;BR /&gt;&amp;nbsp;port-object eq smtp&lt;BR /&gt;access-list internet_in extended permit tcp any host 63.X.X.X object-group mdaemon &lt;BR /&gt;access-list internet_in extended permit tcp any host 63.X.X.Y object-group DM_INLINE_TCP_1 &lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging buffer-size 1040000&lt;BR /&gt;logging monitor debugging&lt;BR /&gt;logging buffered debugging&lt;BR /&gt;logging trap notifications&lt;BR /&gt;logging asdm debugging&lt;BR /&gt;logging host inside 192.168.40.209 17/5544&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu dmz 1500&lt;BR /&gt;mtu guest_inet 1500&lt;BR /&gt;mtu management 1500&lt;BR /&gt;ip local pool VPN_Pool 172.20.1.10-172.20.1.254 mask 255.255.255.0&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-649-103.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (outside) 1 interface&lt;BR /&gt;global (inside) 1 interface&lt;BR /&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;BR /&gt;nat (inside) 1 172.16.0.0 255.255.0.0&lt;BR /&gt;nat (inside) 1 192.168.0.0 255.255.0.0&lt;BR /&gt;nat (guest_inet) 1 10.2.0.0 255.255.254.0&lt;BR /&gt;nat (guest_inet) 1 10.2.0.0 255.255.254.0 outside&lt;BR /&gt;static (inside,outside) tcp 63.X.X.Y smtp 192.168.40.9 smtp netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) tcp 63.X.X.X smtp 192.168.40.8 smtp netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) tcp 63.X.X.X pop3 192.168.40.8 pop3 netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) tcp 63.X.X.X imap4 192.168.40.8 imap4 netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) tcp 63.X.X.X ident 192.168.40.8 ident netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) tcp 63.X.X.X 7071 192.168.40.8 7071 netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) tcp 63.X.X.X 3000 192.168.40.8 3000 netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) tcp 63.X.X.X https 192.168.40.8 https netmask 255.255.255.255 &lt;BR /&gt;access-group internet_in in interface outside&lt;BR /&gt;access-group outside_access_out out interface outside&lt;BR /&gt;access-group guest_inet_access_in in interface guest_inet&lt;BR /&gt;!&lt;BR /&gt;router eigrp 7159&lt;BR /&gt;&amp;nbsp;no auto-summary&lt;BR /&gt;&amp;nbsp;network X.X.X.X 255.255.255.240&lt;BR /&gt;&amp;nbsp;network 172.20.1.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network 192.168.40.0 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 X.X.X.X 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;aaa authentication telnet console LOCAL &lt;BR /&gt;aaa authentication ssh console LOCAL &lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.1.0 255.255.255.0 management&lt;BR /&gt;http 192.168.0.0 255.255.0.0 inside&lt;BR /&gt;snmp-server host inside 192.168.40.200 community ***** version 2c&lt;BR /&gt;snmp-server host inside 192.168.40.217 community ***** version 2c&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server community *****&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac &lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;crypto dynamic-map outside_dyn_map 20 set transform-set ESP-3DES-SHA&lt;BR /&gt;crypto dynamic-map outside_dyn_map 40 set pfs &lt;BR /&gt;crypto dynamic-map outside_dyn_map 40 set transform-set ESP-3DES-SHA&lt;BR /&gt;crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map&lt;BR /&gt;crypto map outside_map interface outside&lt;BR /&gt;crypto ca trustpoint _SmartCallHome_ServerCA&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto isakmp identity hostname &lt;BR /&gt;crypto isakmp enable outside&lt;BR /&gt;crypto isakmp policy 10&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;telnet 192.168.0.0 255.255.0.0 inside&lt;BR /&gt;telnet 172.16.0.0 255.255.0.0 inside&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;BR /&gt;ssh 192.168.0.0 255.255.0.0 inside&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics&lt;BR /&gt;threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200&lt;BR /&gt;ntp server 192.168.40.1 source inside prefer&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;!&lt;BR /&gt;prompt hostname context &lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;call-home&lt;BR /&gt;&amp;nbsp;profile CiscoTAC-1&lt;BR /&gt;&amp;nbsp; no active&lt;BR /&gt;&amp;nbsp; destination address http &lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; destination address email callhome@cisco.com&lt;BR /&gt;&amp;nbsp; destination transport-method http&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;BR /&gt;Cryptochecksum:4bc8f4be3357f45680fa141e97167f4e&lt;BR /&gt;: end&lt;/P&gt;</description>
      <pubDate>Wed, 10 Feb 2016 03:50:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-multiple-emails-with-no-esmtp-inspection/m-p/2807782#M172777</guid>
      <dc:creator>rsaeks</dc:creator>
      <dc:date>2016-02-10T03:50:27Z</dc:date>
    </item>
    <item>
      <title>It is not this device doing</title>
      <link>https://community.cisco.com/t5/network-security/multiple-multiple-emails-with-no-esmtp-inspection/m-p/2807783#M172778</link>
      <description>&lt;P&gt;It is not this device doing the inspection. &amp;nbsp;Do you have any other firewalls or routers it could be?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any chance the ISP you are using is doing this?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Feb 2016 04:16:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-multiple-emails-with-no-esmtp-inspection/m-p/2807783#M172778</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-02-10T04:16:06Z</dc:date>
    </item>
  </channel>
</rss>

