<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi,Have you checked that the in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/remove-smtp-fixup-cisco-881-cli-command/m-p/2692352#M190740</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Have you checked that the mail server is not configured to receive only 2meg from cloud services?&lt;/P&gt;&lt;P&gt;Is the mail server 192.168.1.111 or 10.10.10.5?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can try editing the following policy map as a test to disable smtp fixup for outside to inside zone:&lt;/P&gt;&lt;P&gt;policy-map type inspect sdm-pol-NATOutsideToInside-1&lt;/P&gt;&lt;P&gt;&amp;nbsp;no class type inspect sdm-nat-smtp-1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;</description>
    <pubDate>Mon, 15 Jun 2015 01:36:11 GMT</pubDate>
    <dc:creator>johnd2310</dc:creator>
    <dc:date>2015-06-15T01:36:11Z</dc:date>
    <item>
      <title>remove SMTP Fixup cisco 881 CLI command</title>
      <link>https://community.cisco.com/t5/network-security/remove-smtp-fixup-cisco-881-cli-command/m-p/2692349#M190734</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;We have a client that is experiencing some interesting Email issues.&lt;/P&gt;&lt;P&gt;When they receive email from a cloud service like Google mail or Hotmail or yahoo mail they do not receive any attachments greater than 2 meg.&lt;/P&gt;&lt;P&gt;If I send from&amp;nbsp;our onsite exchange server it works as expected.&lt;/P&gt;&lt;P&gt;As we have run out of other ideas and nothing else seems to fix this I'm suspecting the SMTP fixup.&lt;/P&gt;&lt;P&gt;I need to remove the SMTP Fixup from a Cisco 881.&lt;/P&gt;&lt;P&gt;Does anyone know what the CLI command for this is?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:05:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remove-smtp-fixup-cisco-881-cli-command/m-p/2692349#M190734</guid>
      <dc:creator>fundataca</dc:creator>
      <dc:date>2019-03-12T06:05:19Z</dc:date>
    </item>
    <item>
      <title>Hi, What firewall is the 881</title>
      <link>https://community.cisco.com/t5/network-security/remove-smtp-fixup-cisco-881-cli-command/m-p/2692350#M190737</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What firewall is the 881 running, CBAC or Zone based firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2015 11:29:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remove-smtp-fixup-cisco-881-cli-command/m-p/2692350#M190737</guid>
      <dc:creator>johnd2310</dc:creator>
      <dc:date>2015-06-12T11:29:02Z</dc:date>
    </item>
    <item>
      <title>Hi JohnAs with most things in</title>
      <link>https://community.cisco.com/t5/network-security/remove-smtp-fixup-cisco-881-cli-command/m-p/2692351#M190739</link>
      <description>&lt;P&gt;Hi John&lt;/P&gt;&lt;P&gt;As with most things in life this was dropped in my lap.&lt;/P&gt;&lt;P&gt;I believe it is Zone based&lt;/P&gt;&lt;P&gt;Here is the config&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using 28548 out of 262136 bytes&lt;BR /&gt;!&lt;BR /&gt;version 12.4&lt;BR /&gt;no service pad&lt;BR /&gt;service timestamps debug datetime msec&lt;BR /&gt;service timestamps log datetime msec&lt;BR /&gt;no service password-encryption&lt;BR /&gt;!&lt;BR /&gt;hostname Router&lt;BR /&gt;!&lt;BR /&gt;boot-start-marker&lt;BR /&gt;boot system flash c880data-universalk9-mz.124-24.5.T.bin&lt;BR /&gt;boot-end-marker&lt;BR /&gt;!&lt;BR /&gt;security passwords min-length 1&lt;BR /&gt;logging buffered 4096&lt;BR /&gt;enable secret 5 $1$tRc6$Pk3N1aDAx4E2rAYAJ90mH1&lt;BR /&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default local&lt;BR /&gt;aaa authentication login ciscocp_vpn_xauth_ml_1 local&lt;BR /&gt;aaa authentication login ciscocp_vpn_xauth_ml_2 local&lt;BR /&gt;aaa authorization exec default local&lt;BR /&gt;aaa authorization network ciscocp_vpn_group_ml_1 local&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;BR /&gt;clock timezone PCTime -5&lt;BR /&gt;clock summer-time PCTime date Apr 6 2003 2:00 Oct 26 2003 2:00&lt;BR /&gt;!&lt;BR /&gt;crypto pki trustpoint TP-self-signed-3840840377&lt;BR /&gt;&amp;nbsp;enrollment selfsigned&lt;BR /&gt;&amp;nbsp;subject-name cn=IOS-Self-Signed-Certificate-3840840377&lt;BR /&gt;&amp;nbsp;revocation-check none&lt;BR /&gt;&amp;nbsp;rsakeypair TP-self-signed-3840840377&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto pki certificate chain TP-self-signed-3840840377&lt;BR /&gt;&amp;nbsp;certificate self-signed 01 nvram:IOS-Self-Sig#8.cer&lt;BR /&gt;ip source-route&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip dhcp excluded-address 10.10.20.1 10.10.20.10&lt;BR /&gt;ip dhcp excluded-address 10.10.10.1 10.10.10.19&lt;BR /&gt;ip dhcp excluded-address 10.10.10.91 10.10.10.254&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool sdm-pool&lt;BR /&gt;&amp;nbsp;&amp;nbsp; import all&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network 10.10.10.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; default-router 10.10.10.1&lt;BR /&gt;&amp;nbsp;&amp;nbsp; dns-server 10.10.10.5&lt;BR /&gt;&amp;nbsp;&amp;nbsp; lease 0 2&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool sdm-pool1&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network 10.10.20.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; default-router 10.10.20.1&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;no ip cef&lt;BR /&gt;ip domain name carepath.local&lt;BR /&gt;ip name-server 10.10.10.5&lt;BR /&gt;no ipv6 cef&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;multilink bundle-name authenticated&lt;BR /&gt;parameter-map type protocol-info msn-servers&lt;BR /&gt;&amp;nbsp;server name messenger.hotmail.com&lt;BR /&gt;&amp;nbsp;server name gateway.messenger.hotmail.com&lt;BR /&gt;&amp;nbsp;server name webmessenger.msn.com&lt;/P&gt;&lt;P&gt;parameter-map type protocol-info aol-servers&lt;BR /&gt;&amp;nbsp;server name login.oscar.aol.com&lt;BR /&gt;&amp;nbsp;server name toc.oscar.aol.com&lt;BR /&gt;&amp;nbsp;server name oam-d09a.blue.aol.com&lt;/P&gt;&lt;P&gt;parameter-map type protocol-info yahoo-servers&lt;BR /&gt;&amp;nbsp;server name scs.msg.yahoo.com&lt;BR /&gt;&amp;nbsp;server name scsa.msg.yahoo.com&lt;BR /&gt;&amp;nbsp;server name scsb.msg.yahoo.com&lt;BR /&gt;&amp;nbsp;server name scsc.msg.yahoo.com&lt;BR /&gt;&amp;nbsp;server name scsd.msg.yahoo.com&lt;BR /&gt;&amp;nbsp;server name cs16.msg.dcn.yahoo.com&lt;BR /&gt;&amp;nbsp;server name cs19.msg.dcn.yahoo.com&lt;BR /&gt;&amp;nbsp;server name cs42.msg.dcn.yahoo.com&lt;BR /&gt;&amp;nbsp;server name cs53.msg.dcn.yahoo.com&lt;BR /&gt;&amp;nbsp;server name cs54.msg.dcn.yahoo.com&lt;BR /&gt;&amp;nbsp;server name ads1.vip.scd.yahoo.com&lt;BR /&gt;&amp;nbsp;server name radio1.launch.vip.dal.yahoo.com&lt;BR /&gt;&amp;nbsp;server name in1.msg.vip.re2.yahoo.com&lt;BR /&gt;&amp;nbsp;server name data1.my.vip.sc5.yahoo.com&lt;BR /&gt;&amp;nbsp;server name address1.pim.vip.mud.yahoo.com&lt;BR /&gt;&amp;nbsp;server name edit.messenger.yahoo.com&lt;BR /&gt;&amp;nbsp;server name messenger.yahoo.com&lt;BR /&gt;&amp;nbsp;server name http.pager.yahoo.com&lt;BR /&gt;&amp;nbsp;server name privacy.yahoo.com&lt;BR /&gt;&amp;nbsp;server name csa.yahoo.com&lt;BR /&gt;&amp;nbsp;server name csb.yahoo.com&lt;BR /&gt;&amp;nbsp;server name csc.yahoo.com&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;!&lt;BR /&gt;username forrestja secret 5 $1$0M.C$jSf2s6jBJc.BhOHEQz6Z7/&lt;BR /&gt;username Mckyedo secret 5 $1$.oVV$osTs3rwN6PDW1r1ratB/Y/&lt;BR /&gt;username kabaines secret 5 $1$05fS$aQmBAn5OPzemwHISAcjA91&lt;BR /&gt;username ecousineau secret 5 $1$chbt$y8i/cTvlKaoi7M6IK9XQz0&lt;BR /&gt;username danidepetrillo secret 5 $1$ClAB$cL.ISVieN3dtuXKYboyiO/&lt;BR /&gt;username ddepetrillo secret 5 $1$/8z2$zo9yhdXX0injN5sR.o.gc.&lt;BR /&gt;username dfulogsi secret 5 $1$7kTK$48wgcGO5ne4/p069y6hNX.&lt;BR /&gt;username whryniuk secret 5 $1$4K6u$hQkC7ZproSeYzXuF6C9z61&lt;BR /&gt;username lhryniuk secret 5 $1$XHHt$MFNNStOiC6dgfY93laFrU1&lt;BR /&gt;username amcgowan secret 5 $1$40Fm$O5QuPgLtQU0uq.9KbxW0M1&lt;BR /&gt;username dthomson secret 5 $1$CAZB$VF0qQbZ/zECKv3QfIDhuD.&lt;BR /&gt;username cshirley secret 5 $1$A395$0hL0DnNysybt51exyXWrN1&lt;BR /&gt;username smoore secret 5 $1$YFq4$j7UTBgdbQMikKGyDhAPCP.&lt;BR /&gt;username jzemaitis secret 5 $1$KiOv$Y22d.91YFkVaDcHc9JfL90&lt;BR /&gt;username wpowell secret 5 $1$ECmG$dQvMWSXWQqPSM/SWMm6Ja0&lt;BR /&gt;username vinadmin privilege 15 secret 5 $1$XJMD$kQLDFx1u5IKBNqtMtg4dL0&lt;BR /&gt;username Admin secret 5 $1$O3rB$H003Fl.KI7vNzSxRpsB5t.&lt;BR /&gt;username shirleyco secret 5 $1$aTod$A91adrDfFQrKx31aAe3/z0&lt;BR /&gt;username mferguson secret 5 $1$XISU$UjnnmGN22rzIf7xnX0CEc.&lt;BR /&gt;username kmcdonald secret 5 $1$cv4K$uuotKYnegG6.y4R7YRiyW1&lt;BR /&gt;username mstevelic secret 5 $1$.isq$wi/HGo0IkZWmoBY..QEeD/&lt;BR /&gt;username drorovan secret 5 $1$L799$Sz04d/XVM/g5Y62z5W.1/0&lt;BR /&gt;username jragaz secret 5 $1$hmK5$z/tvrdohCMiEprCW9p9Yq.&lt;BR /&gt;username pmajor secret 5 $1$CxxE$9hgS21SbVhVdOmUaRdvgs/&lt;BR /&gt;username borovan secret 5 $1$fsw9$ZIIUltJ9Cc7nBpmuswIDs.&lt;BR /&gt;username leedo secret 5 $1$xnMk$6IQf2FzK1L5QMgjfRx8.h.&lt;BR /&gt;username jgowing secret 5 $1$EVEP$YjxyE5Lw.hcivE.JqbH0Y/&lt;BR /&gt;username royst secret 5 $1$/wbP$W3daZVjU3bYAtR9x01nEh.&lt;BR /&gt;username rbergeron secret 5 $1$EeAx$ipFbCd0SwjTLUB/8pCMxR0&lt;BR /&gt;username rsimpson secret 5 $1$cvh6$0MVp4eSyhij0NCX6NUDGK1&lt;BR /&gt;username ssaraydarian secret 5 $1$YJV7$v14qULB7TFYsTEVcvyC8o.&lt;BR /&gt;username Leeke secret 5 $1$IH5i$.yJJW7mKF.sD7DIr53AXc0&lt;BR /&gt;username hooman secret 5 $1$eJ3J$OKcje0Q.K5o.IOJJ.it0D1&lt;BR /&gt;username cmills secret 5 $1$QH8Z$QZqY8kJEvpp/WBQIAl7yn0&lt;BR /&gt;username bannayar secret 5 $1$erc7$EhY2OUL2okAuJw6.VFwvW.&lt;BR /&gt;username alstiburek secret 5 $1$5FSX$5RJb1h0NBYyH6q93aXT3U.&lt;BR /&gt;username pcarter secret 5 $1$dVJI$EnovCDfEe3SakN15Q9kkW.&lt;BR /&gt;username janarthans view root secret 5 $1$A5c8$x/d03.bT3e29fTJ2Iunt/1&lt;BR /&gt;username palmerb view root secret 5 $1$MlTf$szxQvyRJBzRnofARAWP0z0&lt;BR /&gt;username lrobichaud privilege 0 secret 5 $1$nztN$hieW9P/XYakZ8aDxvc/hc/&lt;BR /&gt;username jtriolo view root secret 5 $1$ZvQL$HdQRobkvBLjTRBvX2CpK/0&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto isakmp policy 1&lt;BR /&gt;&amp;nbsp;encr 3des&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;!&lt;BR /&gt;crypto isakmp policy 3&lt;BR /&gt;&amp;nbsp;encr 3des&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;crypto isakmp key *********** address x.x.x.x.x&lt;BR /&gt;!&lt;BR /&gt;crypto isakmp client configuration group VPNGroup&lt;BR /&gt;&amp;nbsp;key CpV1nA$$4&lt;BR /&gt;&amp;nbsp;dns 10.10.10.5&lt;BR /&gt;&amp;nbsp;domain Carepath.local&lt;BR /&gt;&amp;nbsp;pool SDM_POOL_1&lt;BR /&gt;&amp;nbsp;acl 100&lt;BR /&gt;&amp;nbsp;max-users 28&lt;BR /&gt;&amp;nbsp;netmask 255.255.255.0&lt;BR /&gt;crypto isakmp profile ciscocp-ike-profile-1&lt;BR /&gt;&amp;nbsp;&amp;nbsp; match identity group VPNGroup&lt;BR /&gt;&amp;nbsp;&amp;nbsp; client authentication list ciscocp_vpn_xauth_ml_1&lt;BR /&gt;&amp;nbsp;&amp;nbsp; isakmp authorization list ciscocp_vpn_group_ml_1&lt;BR /&gt;&amp;nbsp;&amp;nbsp; client configuration address respond&lt;BR /&gt;&amp;nbsp;&amp;nbsp; virtual-template 1&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac&lt;BR /&gt;crypto ipsec transform-set ESP-3DES-SHA1 esp-3des esp-sha-hmac&lt;BR /&gt;!&lt;BR /&gt;crypto ipsec profile CiscoCP_Profile1&lt;BR /&gt;&amp;nbsp;set transform-set ESP-3DES-SHA&lt;BR /&gt;&amp;nbsp;set isakmp-profile ciscocp-ike-profile-1&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto map SDM_CMAP_1 1 ipsec-isakmp&lt;BR /&gt;&amp;nbsp;description Apply the crypto map on the peer router's interface having IP address x.x.x.x that connects to this router.&lt;BR /&gt;&amp;nbsp;set peer 216.123.165.9&lt;BR /&gt;&amp;nbsp;set transform-set ESP-3DES-SHA1&lt;BR /&gt;&amp;nbsp;match address SDM_4&lt;BR /&gt;!&lt;BR /&gt;archive&lt;BR /&gt;&amp;nbsp;log config&lt;BR /&gt;&amp;nbsp; hidekeys&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip ftp username cisco&lt;BR /&gt;ip ftp password &amp;lt;removed&amp;gt;&lt;BR /&gt;!&lt;BR /&gt;class-map type inspect match-all sdm-cls-VPNOutsideToInside-1&lt;BR /&gt;&amp;nbsp;match access-group 107&lt;BR /&gt;class-map type inspect match-all sdm-cls-VPNOutsideToInside-3&lt;BR /&gt;&amp;nbsp;match access-group 109&lt;BR /&gt;class-map type inspect match-all sdm-cls-VPNOutsideToInside-2&lt;BR /&gt;&amp;nbsp;match access-group 108&lt;BR /&gt;class-map type inspect imap match-any ccp-app-imap&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; invalid-command&lt;BR /&gt;class-map type inspect match-any ccp-cls-protocol-p2p&lt;BR /&gt;&amp;nbsp;match protocol edonkey signature&lt;BR /&gt;&amp;nbsp;match protocol gnutella signature&lt;BR /&gt;&amp;nbsp;match protocol kazaa2 signature&lt;BR /&gt;&amp;nbsp;match protocol fasttrack signature&lt;BR /&gt;&amp;nbsp;match protocol bittorrent signature&lt;BR /&gt;class-map type inspect match-all sdm-nat-http-1&lt;BR /&gt;&amp;nbsp;match access-group 103&lt;BR /&gt;&amp;nbsp;match protocol http&lt;BR /&gt;class-map type inspect match-any https&lt;BR /&gt;&amp;nbsp;match protocol https&lt;BR /&gt;class-map type inspect match-all sdm-cls-sdm-pol-NATOutsideToInside-1-1&lt;BR /&gt;&amp;nbsp;match class-map https&lt;BR /&gt;&amp;nbsp;match access-group name WANtoOWA&lt;BR /&gt;class-map type inspect match-all sdm-nat-http-2&lt;BR /&gt;&amp;nbsp;match access-group 104&lt;BR /&gt;&amp;nbsp;match protocol http&lt;BR /&gt;class-map type inspect match-all sdm-nat-smtp-1&lt;BR /&gt;&amp;nbsp;match access-group 102&lt;BR /&gt;&amp;nbsp;match protocol tcp&lt;BR /&gt;class-map type inspect match-any SDM_AH&lt;BR /&gt;&amp;nbsp;match access-group name SDM_AH&lt;BR /&gt;class-map type inspect match-any CCP-Voice-permit&lt;BR /&gt;&amp;nbsp;match protocol h323&lt;BR /&gt;&amp;nbsp;match protocol skinny&lt;BR /&gt;&amp;nbsp;match protocol sip&lt;BR /&gt;class-map type inspect match-any SDM_ESP&lt;BR /&gt;&amp;nbsp;match access-group name SDM_ESP&lt;BR /&gt;class-map type inspect match-any SDM_VPN_TRAFFIC&lt;BR /&gt;&amp;nbsp;match protocol isakmp&lt;BR /&gt;&amp;nbsp;match protocol ipsec-msft&lt;BR /&gt;&amp;nbsp;match class-map SDM_AH&lt;BR /&gt;&amp;nbsp;match class-map SDM_ESP&lt;BR /&gt;class-map type inspect match-all SDM_VPN_PT&lt;BR /&gt;&amp;nbsp;match access-group 106&lt;BR /&gt;&amp;nbsp;match class-map SDM_VPN_TRAFFIC&lt;BR /&gt;class-map type inspect match-any http&lt;BR /&gt;&amp;nbsp;match protocol dns&lt;BR /&gt;&amp;nbsp;match protocol http&lt;BR /&gt;&amp;nbsp;match protocol https&lt;BR /&gt;&amp;nbsp;match protocol icmp&lt;BR /&gt;&amp;nbsp;match protocol smtp&lt;BR /&gt;class-map type inspect match-any ccp-cls-insp-traffic&lt;BR /&gt;&amp;nbsp;match protocol cuseeme&lt;BR /&gt;&amp;nbsp;match protocol dns&lt;BR /&gt;&amp;nbsp;match protocol ftp&lt;BR /&gt;&amp;nbsp;match protocol h323&lt;BR /&gt;&amp;nbsp;match protocol https&lt;BR /&gt;&amp;nbsp;match protocol icmp&lt;BR /&gt;&amp;nbsp;match protocol imap&lt;BR /&gt;&amp;nbsp;match protocol pop3&lt;BR /&gt;&amp;nbsp;match protocol netshow&lt;BR /&gt;&amp;nbsp;match protocol shell&lt;BR /&gt;&amp;nbsp;match protocol realmedia&lt;BR /&gt;&amp;nbsp;match protocol rtsp&lt;BR /&gt;&amp;nbsp;match protocol smtp extended&lt;BR /&gt;&amp;nbsp;match protocol sql-net&lt;BR /&gt;&amp;nbsp;match protocol streamworks&lt;BR /&gt;&amp;nbsp;match protocol tftp&lt;BR /&gt;&amp;nbsp;match protocol vdolive&lt;BR /&gt;&amp;nbsp;match protocol tcp&lt;BR /&gt;&amp;nbsp;match protocol udp&lt;BR /&gt;class-map type inspect match-all ccp-insp-traffic&lt;BR /&gt;&amp;nbsp;match class-map ccp-cls-insp-traffic&lt;BR /&gt;class-map type inspect match-all sdm-cls--2&lt;BR /&gt;&amp;nbsp;match class-map http&lt;BR /&gt;&amp;nbsp;match access-group name DMZOutbound&lt;BR /&gt;class-map type inspect match-all sdm-cls--1&lt;BR /&gt;&amp;nbsp;match access-group name VPNZtoDMZ&lt;BR /&gt;class-map type inspect match-any SDM_IP&lt;BR /&gt;&amp;nbsp;match access-group name SDM_IP&lt;BR /&gt;class-map type inspect gnutella match-any ccp-app-gnutella&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; file-transfer&lt;BR /&gt;class-map type inspect match-any SDM_EASY_VPN_SERVER_TRAFFIC&lt;BR /&gt;&amp;nbsp;match protocol isakmp&lt;BR /&gt;&amp;nbsp;match protocol ipsec-msft&lt;BR /&gt;&amp;nbsp;match class-map SDM_AH&lt;BR /&gt;&amp;nbsp;match class-map SDM_ESP&lt;BR /&gt;class-map type inspect match-all SDM_EASY_VPN_SERVER_PT&lt;BR /&gt;&amp;nbsp;match class-map SDM_EASY_VPN_SERVER_TRAFFIC&lt;BR /&gt;class-map type inspect msnmsgr match-any ccp-app-msn-otherservices&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; service any&lt;BR /&gt;class-map type inspect ymsgr match-any ccp-app-yahoo-otherservices&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; service any&lt;BR /&gt;class-map type inspect match-all ipsec-class&lt;BR /&gt;&amp;nbsp;match protocol isakmp&lt;BR /&gt;&amp;nbsp;match protocol ipsec-msft&lt;BR /&gt;class-map type inspect match-any ccp-cls-icmp-access&lt;BR /&gt;&amp;nbsp;match protocol icmp&lt;BR /&gt;&amp;nbsp;match protocol tcp&lt;BR /&gt;&amp;nbsp;match protocol udp&lt;BR /&gt;class-map type inspect match-any ccp-cls-protocol-im&lt;BR /&gt;&amp;nbsp;match protocol ymsgr yahoo-servers&lt;BR /&gt;&amp;nbsp;match protocol msnmsgr msn-servers&lt;BR /&gt;&amp;nbsp;match protocol aol aol-servers&lt;BR /&gt;class-map type inspect aol match-any ccp-app-aol-otherservices&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; service any&lt;BR /&gt;class-map type inspect match-all webvpn-8081&lt;BR /&gt;&amp;nbsp;match access-group 150&lt;BR /&gt;class-map type inspect match-all ccp-protocol-pop3&lt;BR /&gt;&amp;nbsp;match protocol pop3&lt;BR /&gt;class-map type inspect match-any sdm-ssl-vpn-traffic&lt;BR /&gt;&amp;nbsp;match access-group 121&lt;BR /&gt;class-map type inspect pop3 match-any ccp-app-pop3&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; invalid-command&lt;BR /&gt;class-map type inspect kazaa2 match-any ccp-app-kazaa2&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; file-transfer&lt;BR /&gt;class-map type inspect match-all ccp-protocol-p2p&lt;BR /&gt;&amp;nbsp;match class-map ccp-cls-protocol-p2p&lt;BR /&gt;class-map type inspect msnmsgr match-any ccp-app-msn&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; service text-chat&lt;BR /&gt;class-map type inspect ymsgr match-any ccp-app-yahoo&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; service text-chat&lt;BR /&gt;class-map type inspect match-any WebsiteViewer&lt;BR /&gt;&amp;nbsp;match protocol smtp&lt;BR /&gt;&amp;nbsp;match protocol https&lt;BR /&gt;&amp;nbsp;match protocol http&lt;BR /&gt;&amp;nbsp;match protocol ftp&lt;BR /&gt;class-map type inspect match-all ccp-protocol-im&lt;BR /&gt;&amp;nbsp;match class-map ccp-cls-protocol-im&lt;BR /&gt;class-map type inspect match-all ccp-invalid-src&lt;BR /&gt;&amp;nbsp;match access-group 101&lt;BR /&gt;class-map type inspect match-all ccp-icmp-access&lt;BR /&gt;&amp;nbsp;match class-map ccp-cls-icmp-access&lt;BR /&gt;class-map type inspect http match-any ccp-app-httpmethods&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method bcopy&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method bdelete&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method bmove&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method bpropfind&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method bproppatch&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method connect&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method copy&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method delete&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method edit&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method getattribute&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method getattributenames&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method getproperties&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method index&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method lock&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method mkcol&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method mkdir&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method move&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method notify&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method options&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method poll&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method propfind&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method proppatch&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method put&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method revadd&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method revlabel&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method revlog&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method revnum&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method save&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method search&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method setattribute&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method startrev&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method stoprev&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method subscribe&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method trace&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method unedit&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method unlock&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request method unsubscribe&lt;BR /&gt;class-map type inspect match-any ccp-dmz-protocols&lt;BR /&gt;&amp;nbsp;match protocol http&lt;BR /&gt;class-map type inspect edonkey match-any ccp-app-edonkey&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; file-transfer&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; text-chat&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; search-file-name&lt;BR /&gt;class-map type inspect http match-any ccp-http-blockparam&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request port-misuse im&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request port-misuse p2p&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; req-resp protocol-violation&lt;BR /&gt;class-map type inspect match-all ccp-dmz-traffic&lt;BR /&gt;&amp;nbsp;match access-group name dmz-traffic&lt;BR /&gt;&amp;nbsp;match class-map ccp-dmz-protocols&lt;BR /&gt;class-map type inspect match-all sdm-cls-ccp-permit-dmzservice-2&lt;BR /&gt;&amp;nbsp;match access-group name VPNtoDMZ&lt;BR /&gt;class-map type inspect match-all sdm-cls-ccp-permit-dmzservice-3&lt;BR /&gt;&amp;nbsp;match class-map WebsiteViewer&lt;BR /&gt;&amp;nbsp;match access-group name WebsiteViewer&lt;BR /&gt;class-map type inspect edonkey match-any ccp-app-edonkeydownload&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; file-transfer&lt;BR /&gt;class-map type inspect match-all ccp-protocol-imap&lt;BR /&gt;&amp;nbsp;match protocol imap&lt;BR /&gt;class-map type inspect aol match-any ccp-app-aol&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; service text-chat&lt;BR /&gt;class-map type inspect match-all sdm-cls-ccp-permit-dmzservice-1&lt;BR /&gt;&amp;nbsp;match access-group name LANtoDMZ&lt;BR /&gt;class-map type inspect edonkey match-any ccp-app-edonkeychat&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; search-file-name&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; text-chat&lt;BR /&gt;class-map type inspect http match-any ccp-http-allowparam&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; request port-misuse tunneling&lt;BR /&gt;class-map type inspect match-all ccp-protocol-http&lt;BR /&gt;&amp;nbsp;match protocol http&lt;BR /&gt;class-map type inspect fasttrack match-any ccp-app-fasttrack&lt;BR /&gt;&amp;nbsp;match&amp;nbsp; file-transfer&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect ccp-permit-icmpreply&lt;BR /&gt;&amp;nbsp;class type inspect ccp-icmp-access&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class class-default&lt;BR /&gt;&amp;nbsp; pass&lt;BR /&gt;policy-map type inspect sdm-pol-VPNOutsideToInside-1&lt;BR /&gt;&amp;nbsp;class type inspect sdm-cls-VPNOutsideToInside-1&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect sdm-cls-VPNOutsideToInside-2&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect sdm-cls-VPNOutsideToInside-3&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class class-default&lt;BR /&gt;&amp;nbsp; drop&lt;BR /&gt;policy-map type inspect p2p ccp-action-app-p2p&lt;BR /&gt;&amp;nbsp;class type inspect edonkey ccp-app-edonkeychat&lt;BR /&gt;&amp;nbsp; log&lt;BR /&gt;&amp;nbsp; allow&lt;BR /&gt;&amp;nbsp;class type inspect edonkey ccp-app-edonkeydownload&lt;BR /&gt;&amp;nbsp; log&lt;BR /&gt;&amp;nbsp; allow&lt;BR /&gt;&amp;nbsp;class type inspect fasttrack ccp-app-fasttrack&lt;BR /&gt;&amp;nbsp; log&lt;BR /&gt;&amp;nbsp; allow&lt;BR /&gt;&amp;nbsp;class type inspect gnutella ccp-app-gnutella&lt;BR /&gt;&amp;nbsp; log&lt;BR /&gt;&amp;nbsp; allow&lt;BR /&gt;&amp;nbsp;class type inspect kazaa2 ccp-app-kazaa2&lt;BR /&gt;&amp;nbsp; log&lt;BR /&gt;&amp;nbsp; allow&lt;BR /&gt;policy-map type inspect sdm-pol-NATOutsideToInside-1&lt;BR /&gt;&amp;nbsp;class type inspect sdm-cls-sdm-pol-NATOutsideToInside-1-1&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect sdm-nat-smtp-1&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect sdm-nat-http-1&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect sdm-nat-http-2&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect sdm-ssl-vpn-traffic&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect ccp-icmp-access&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect sdm-cls-VPNOutsideToInside-1&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect sdm-cls-VPNOutsideToInside-2&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect sdm-cls-VPNOutsideToInside-3&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class class-default&lt;BR /&gt;&amp;nbsp; drop&lt;BR /&gt;policy-map type inspect im ccp-action-app-im&lt;BR /&gt;&amp;nbsp;class type inspect aol ccp-app-aol&lt;BR /&gt;&amp;nbsp; log&lt;BR /&gt;&amp;nbsp; allow&lt;BR /&gt;&amp;nbsp;class type inspect msnmsgr ccp-app-msn&lt;BR /&gt;&amp;nbsp; log&lt;BR /&gt;&amp;nbsp; allow&lt;BR /&gt;&amp;nbsp;class type inspect ymsgr ccp-app-yahoo&lt;BR /&gt;&amp;nbsp; log&lt;BR /&gt;&amp;nbsp; allow&lt;BR /&gt;&amp;nbsp;class type inspect aol ccp-app-aol-otherservices&lt;BR /&gt;&amp;nbsp; log&lt;BR /&gt;&amp;nbsp; reset&lt;BR /&gt;&amp;nbsp;class type inspect msnmsgr ccp-app-msn-otherservices&lt;BR /&gt;&amp;nbsp; log&lt;BR /&gt;&amp;nbsp; reset&lt;BR /&gt;&amp;nbsp;class type inspect ymsgr ccp-app-yahoo-otherservices&lt;BR /&gt;&amp;nbsp; log&lt;BR /&gt;&amp;nbsp; reset&lt;BR /&gt;policy-map type inspect imap ccp-action-imap&lt;BR /&gt;&amp;nbsp;class type inspect imap ccp-app-imap&lt;BR /&gt;&amp;nbsp; log&lt;BR /&gt;policy-map type inspect pop3 ccp-action-pop3&lt;BR /&gt;&amp;nbsp;class type inspect pop3 ccp-app-pop3&lt;BR /&gt;&amp;nbsp; log&lt;BR /&gt;policy-map type inspect ccp-inspect&lt;BR /&gt;&amp;nbsp;class type inspect ccp-invalid-src&lt;BR /&gt;&amp;nbsp; drop log&lt;BR /&gt;&amp;nbsp;class type inspect ccp-protocol-http&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect ccp-protocol-imap&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp; service-policy imap ccp-action-imap&lt;BR /&gt;&amp;nbsp;class type inspect ccp-protocol-pop3&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp; service-policy pop3 ccp-action-pop3&lt;BR /&gt;&amp;nbsp;class type inspect ccp-protocol-p2p&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp; service-policy p2p ccp-action-app-p2p&lt;BR /&gt;&amp;nbsp;class type inspect ccp-protocol-im&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp; service-policy im ccp-action-app-im&lt;BR /&gt;&amp;nbsp;class type inspect ccp-insp-traffic&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class class-default&lt;BR /&gt;&amp;nbsp; drop&lt;BR /&gt;policy-map type inspect http ccp-action-app-http&lt;BR /&gt;&amp;nbsp;class type inspect http ccp-http-blockparam&lt;BR /&gt;&amp;nbsp; log&lt;BR /&gt;&amp;nbsp; allow&lt;BR /&gt;&amp;nbsp;class type inspect http ccp-app-httpmethods&lt;BR /&gt;&amp;nbsp; log&lt;BR /&gt;&amp;nbsp; reset&lt;BR /&gt;&amp;nbsp;class type inspect http ccp-http-allowparam&lt;BR /&gt;&amp;nbsp; log&lt;BR /&gt;&amp;nbsp; allow&lt;BR /&gt;policy-map type inspect ccp-permit&lt;BR /&gt;&amp;nbsp;class type inspect SDM_EASY_VPN_SERVER_PT&lt;BR /&gt;&amp;nbsp; pass&lt;BR /&gt;&amp;nbsp;class class-default&lt;BR /&gt;&amp;nbsp; drop&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;policy-map type inspect sdm-policy-sdm-cls--1&lt;BR /&gt;&amp;nbsp;class type inspect sdm-cls--1&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class class-default&lt;BR /&gt;&amp;nbsp; drop&lt;BR /&gt;policy-map type inspect sdm-pol-Out-to-Self&lt;BR /&gt;&amp;nbsp;class type inspect SDM_VPN_PT&lt;BR /&gt;&amp;nbsp; pass&lt;BR /&gt;&amp;nbsp;class type inspect webvpn-8081&lt;BR /&gt;&amp;nbsp;class type inspect SDM_EASY_VPN_SERVER_TRAFFIC&lt;BR /&gt;&amp;nbsp; pass&lt;BR /&gt;&amp;nbsp;class class-default&lt;BR /&gt;&amp;nbsp; drop&lt;BR /&gt;policy-map type inspect sdm-pol-ssl-vpn-traffic&lt;BR /&gt;&amp;nbsp;class type inspect sdm-ssl-vpn-traffic&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class class-default&lt;BR /&gt;&amp;nbsp; drop&lt;BR /&gt;policy-map type inspect sdm-policy-sdm-cls--2&lt;BR /&gt;&amp;nbsp;class type inspect sdm-cls--2&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class class-default&lt;BR /&gt;&amp;nbsp; drop&lt;BR /&gt;policy-map type inspect ccp-permit-dmzservice&lt;BR /&gt;&amp;nbsp;class type inspect sdm-cls-ccp-permit-dmzservice-3&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect sdm-cls-ccp-permit-dmzservice-2&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect sdm-cls-ccp-permit-dmzservice-1&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect ccp-dmz-traffic&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect CCP-Voice-permit&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect sdm-nat-smtp-1&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect sdm-nat-http-1&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect sdm-cls-VPNOutsideToInside-1&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect sdm-cls-VPNOutsideToInside-2&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect sdm-cls-VPNOutsideToInside-3&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class class-default&lt;BR /&gt;&amp;nbsp; pass&lt;BR /&gt;policy-map type inspect sdm-permit-ip&lt;BR /&gt;&amp;nbsp;class type inspect SDM_IP&lt;BR /&gt;&amp;nbsp; pass&lt;BR /&gt;&amp;nbsp;class type inspect sdm-cls-VPNOutsideToInside-1&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect sdm-cls-VPNOutsideToInside-2&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class type inspect sdm-cls-VPNOutsideToInside-3&lt;BR /&gt;&amp;nbsp; inspect&lt;BR /&gt;&amp;nbsp;class class-default&lt;BR /&gt;&amp;nbsp; drop log&lt;BR /&gt;!&lt;BR /&gt;zone security dmz-zone&lt;BR /&gt;zone security out-zone&lt;BR /&gt;zone security in-zone&lt;BR /&gt;zone security ezvpn-zone&lt;BR /&gt;zone security ssl-zone&lt;BR /&gt;zone-pair security ccp-zp-self-out source self destination out-zone&lt;BR /&gt;&amp;nbsp;service-policy type inspect ccp-permit-icmpreply&lt;BR /&gt;zone-pair security sdm-zp-NATOutsideToInside-1 source out-zone destination in-zone&lt;BR /&gt;&amp;nbsp;service-policy type inspect sdm-pol-NATOutsideToInside-1&lt;BR /&gt;zone-pair security ccp-zp-in-dmz source in-zone destination dmz-zone&lt;BR /&gt;&amp;nbsp;service-policy type inspect ccp-permit-dmzservice&lt;BR /&gt;zone-pair security ccp-zp-in-out source in-zone destination out-zone&lt;BR /&gt;&amp;nbsp;service-policy type inspect ccp-inspect&lt;BR /&gt;zone-pair security ccp-zp-out-dmz source out-zone destination dmz-zone&lt;BR /&gt;&amp;nbsp;service-policy type inspect ccp-permit-dmzservice&lt;BR /&gt;zone-pair security ccp-zp-out-self source out-zone destination self&lt;BR /&gt;&amp;nbsp;service-policy type inspect sdm-pol-Out-to-Self&lt;BR /&gt;zone-pair security sdm-zp-ezvpn-out1 source ezvpn-zone destination out-zone&lt;BR /&gt;&amp;nbsp;service-policy type inspect sdm-permit-ip&lt;BR /&gt;zone-pair security sdm-zp-out-ezpn1 source out-zone destination ezvpn-zone&lt;BR /&gt;&amp;nbsp;service-policy type inspect sdm-permit-ip&lt;BR /&gt;zone-pair security sdm-zp-ezvpn-in1 source ezvpn-zone destination in-zone&lt;BR /&gt;&amp;nbsp;service-policy type inspect sdm-permit-ip&lt;BR /&gt;zone-pair security sdm-zp-in-ezvpn1 source in-zone destination ezvpn-zone&lt;BR /&gt;&amp;nbsp;service-policy type inspect sdm-permit-ip&lt;BR /&gt;zone-pair security sdm-zp-ezvpn-zone-dmz-zone source ezvpn-zone destination dmz-zone&lt;BR /&gt;&amp;nbsp;service-policy type inspect sdm-policy-sdm-cls--1&lt;BR /&gt;zone-pair security sdm-zp-sll-zone-in-zone source ssl-zone destination in-zone&lt;BR /&gt;&amp;nbsp;service-policy type inspect sdm-pol-ssl-vpn-traffic&lt;BR /&gt;zone-pair security sdm-zp-dmz-zone-out-zone source dmz-zone destination out-zone&lt;BR /&gt;&amp;nbsp;service-policy type inspect sdm-policy-sdm-cls--2&lt;BR /&gt;zone-pair security sdm-zp-VPNOutsideToInside-1 source out-zone destination ssl-zone&lt;BR /&gt;&amp;nbsp;service-policy type inspect sdm-pol-VPNOutsideToInside-1&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface Loopback0&lt;BR /&gt;&amp;nbsp;ip address 10.10.50.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0&lt;BR /&gt;&amp;nbsp;switchport access vlan 2&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet1&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet2&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet3&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet4&lt;BR /&gt;&amp;nbsp;description $FW_OUTSIDE$$ETH-WAN$&lt;BR /&gt;&amp;nbsp;ip address 63.250.109.214 255.255.255.248&lt;BR /&gt;&amp;nbsp;ip nat outside&lt;BR /&gt;&amp;nbsp;ip virtual-reassembly&lt;BR /&gt;&amp;nbsp;zone-member security out-zone&lt;BR /&gt;&amp;nbsp;duplex auto&lt;BR /&gt;&amp;nbsp;speed auto&lt;BR /&gt;&amp;nbsp;crypto map SDM_CMAP_1&lt;BR /&gt;!&lt;BR /&gt;interface Virtual-Template1 type tunnel&lt;BR /&gt;&amp;nbsp;ip unnumbered FastEthernet4&lt;BR /&gt;&amp;nbsp;zone-member security ezvpn-zone&lt;BR /&gt;&amp;nbsp;tunnel mode ipsec ipv4&lt;BR /&gt;&amp;nbsp;tunnel protection ipsec profile CiscoCP_Profile1&lt;BR /&gt;!&lt;BR /&gt;interface Virtual-Template5&lt;BR /&gt;&amp;nbsp;ip unnumbered FastEthernet4&lt;BR /&gt;&amp;nbsp;zone-member security ssl-zone&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt;&amp;nbsp;description $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$$FW_INSIDE$&lt;BR /&gt;&amp;nbsp;ip address 10.10.10.1 255.255.255.0&lt;BR /&gt;&amp;nbsp;ip nat inside&lt;BR /&gt;&amp;nbsp;ip virtual-reassembly&lt;BR /&gt;&amp;nbsp;zone-member security in-zone&lt;BR /&gt;&amp;nbsp;ip tcp adjust-mss 1452&lt;BR /&gt;!&lt;BR /&gt;interface Vlan2&lt;BR /&gt;&amp;nbsp;description $FW_DMZ$&lt;BR /&gt;&amp;nbsp;ip address 10.10.20.1 255.255.255.0&lt;BR /&gt;&amp;nbsp;ip nat inside&lt;BR /&gt;&amp;nbsp;ip virtual-reassembly&lt;BR /&gt;&amp;nbsp;zone-member security dmz-zone&lt;BR /&gt;!&lt;BR /&gt;ip local pool SDM_POOL_1 10.10.50.2 10.10.50.30&lt;BR /&gt;ip forward-protocol nd&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 FastEthernet4 63.250.109.209&lt;BR /&gt;ip route 10.10.1.0 255.255.255.0 10.10.10.254&lt;BR /&gt;ip http server&lt;BR /&gt;ip http access-class 23&lt;BR /&gt;ip http authentication local&lt;BR /&gt;ip http secure-server&lt;BR /&gt;ip http timeout-policy idle 60 life 86400 requests 10000&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip nat inside source static tcp 10.10.10.5 25 interface FastEthernet4 25&lt;BR /&gt;ip nat inside source static tcp 10.10.20.100 80 interface FastEthernet4 80&lt;BR /&gt;ip nat inside source static tcp 10.10.20.100 443 interface FastEthernet4 443&lt;BR /&gt;ip nat inside source route-map SDM_RMAP_1 interface FastEthernet4 overload&lt;BR /&gt;ip nat inside source static tcp 10.10.10.5 9091 63.250.109.214 9091 extendable&lt;BR /&gt;!&lt;BR /&gt;ip access-list extended DMZOutbound&lt;BR /&gt;&amp;nbsp;remark CCP_ACL Category=128&lt;BR /&gt;&amp;nbsp;permit ip host 10.10.20.4 any&lt;BR /&gt;&amp;nbsp;permit ip host 10.10.20.5 any&lt;BR /&gt;ip access-list extended LANtoDMZ&lt;BR /&gt;&amp;nbsp;remark CCP_ACL Category=128&lt;BR /&gt;&amp;nbsp;permit ip any host 10.10.20.5&lt;BR /&gt;&amp;nbsp;permit ip any host 10.10.20.4&lt;BR /&gt;&amp;nbsp;permit ip any host 10.10.20.100&lt;BR /&gt;ip access-list extended SDM_4&lt;BR /&gt;&amp;nbsp;remark CCP_ACL Category=4&lt;BR /&gt;&amp;nbsp;remark IPSec Rule&lt;BR /&gt;&amp;nbsp;permit ip 10.10.10.0 0.0.0.255 10.10.11.0 0.0.0.255&lt;BR /&gt;ip access-list extended SDM_AH&lt;BR /&gt;&amp;nbsp;remark CCP_ACL Category=1&lt;BR /&gt;&amp;nbsp;permit ahp any any&lt;BR /&gt;ip access-list extended SDM_ESP&lt;BR /&gt;&amp;nbsp;remark CCP_ACL Category=1&lt;BR /&gt;&amp;nbsp;permit esp any any&lt;BR /&gt;ip access-list extended SDM_IP&lt;BR /&gt;&amp;nbsp;remark CCP_ACL Category=1&lt;BR /&gt;&amp;nbsp;permit ip any any&lt;BR /&gt;ip access-list extended SIP-Traffic&lt;BR /&gt;&amp;nbsp;remark CCP_ACL Category=1&lt;BR /&gt;&amp;nbsp;permit tcp host 204.101.238.132 any&lt;BR /&gt;&amp;nbsp;permit udp host 204.101.238.132 any eq 5060&lt;BR /&gt;&amp;nbsp;remark Sip Traffic Deny&lt;BR /&gt;&amp;nbsp;deny&amp;nbsp;&amp;nbsp; tcp any any eq 5060&lt;BR /&gt;ip access-list extended VPNZtoDMZ&lt;BR /&gt;&amp;nbsp;remark CCP_ACL Category=128&lt;BR /&gt;&amp;nbsp;permit ip any host 10.10.20.5&lt;BR /&gt;&amp;nbsp;permit ip any host 10.10.20.4&lt;BR /&gt;ip access-list extended VPNtoDMZ&lt;BR /&gt;&amp;nbsp;remark CCP_ACL Category=128&lt;BR /&gt;&amp;nbsp;permit ip any host 10.10.20.5&lt;BR /&gt;ip access-list extended WANtoOWA&lt;BR /&gt;&amp;nbsp;remark CCP_ACL Category=128&lt;BR /&gt;&amp;nbsp;permit ip any host 10.10.10.5&lt;BR /&gt;ip access-list extended WebsiteViewer&lt;BR /&gt;&amp;nbsp;remark CCP_ACL Category=128&lt;BR /&gt;&amp;nbsp;permit ip host 10.10.20.5 any&lt;BR /&gt;&amp;nbsp;permit ip host 10.10.20.4 any&lt;BR /&gt;ip access-list extended dmz-traffic&lt;BR /&gt;&amp;nbsp;remark CCP_ACL Category=1&lt;BR /&gt;&amp;nbsp;permit ip any host 10.10.20.1&lt;BR /&gt;&amp;nbsp;permit ip any host 10.10.20.2&lt;BR /&gt;&amp;nbsp;permit ip any host 10.10.20.3&lt;BR /&gt;&amp;nbsp;permit ip any host 10.10.20.4&lt;BR /&gt;&amp;nbsp;permit ip any host 10.10.20.5&lt;BR /&gt;&amp;nbsp;permit ip any host 10.10.20.6&lt;BR /&gt;&amp;nbsp;permit ip any host 10.10.20.7&lt;BR /&gt;&amp;nbsp;permit ip any host 10.10.20.8&lt;BR /&gt;&amp;nbsp;permit ip any host 10.10.20.9&lt;BR /&gt;&amp;nbsp;permit ip any host 10.10.20.10&lt;BR /&gt;!&lt;BR /&gt;access-list 1 remark INSIDE_IF=Vlan1&lt;BR /&gt;access-list 1 remark CCP_ACL Category=2&lt;BR /&gt;access-list 1 permit 10.10.10.0 0.0.0.255&lt;BR /&gt;access-list 2 remark CCP_ACL Category=2&lt;BR /&gt;access-list 2 permit 10.10.20.0 0.0.0.255&lt;BR /&gt;access-list 23 remark CCP_ACL Category=17&lt;BR /&gt;access-list 23 permit 10.10.10.0 0.0.0.255&lt;BR /&gt;access-list 23 permit 10.10.20.0 0.0.0.255&lt;BR /&gt;access-list 23 permit 10.10.50.0 0.0.0.255&lt;BR /&gt;access-list 100 remark CCP_ACL Category=4&lt;BR /&gt;access-list 100 permit ip 10.10.10.0 0.0.0.255 any&lt;BR /&gt;access-list 100 permit ip 10.10.20.0 0.0.0.255 any&lt;BR /&gt;access-list 101 remark CCP_ACL Category=128&lt;BR /&gt;access-list 101 permit ip host 255.255.255.255 any&lt;BR /&gt;access-list 101 permit ip 127.0.0.0 0.255.255.255 any&lt;BR /&gt;access-list 101 permit ip 10.10.20.0 0.0.0.255 any&lt;BR /&gt;access-list 101 permit ip 207.164.203.24 0.0.0.7 any&lt;BR /&gt;access-list 102 remark CPP_ACL Category=0&lt;BR /&gt;access-list 102 permit tcp any host 192.168.1.111 eq smtp&lt;BR /&gt;access-list 103 remark CCP_ACL Category=0&lt;BR /&gt;access-list 103 permit ip any host 10.10.20.5&lt;BR /&gt;access-list 104 remark CCP_ACL Category=0&lt;BR /&gt;access-list 104 permit ip any host 10.10.20.100&lt;BR /&gt;access-list 105 remark CCP_ACL Category=4&lt;BR /&gt;access-list 105 permit ip host 10.10.10.0 any&lt;BR /&gt;access-list 105 permit ip host 10.10.20.0 any&lt;BR /&gt;access-list 105 permit ip host 10.10.50.0 any&lt;BR /&gt;access-list 106 remark CCP_ACL Category=128&lt;BR /&gt;access-list 106 permit ip host 216.123.165.9 any&lt;BR /&gt;access-list 107 remark CCP_ACL Category=0&lt;BR /&gt;access-list 107 permit ip 10.10.11.0 0.0.0.255 10.10.10.0 0.0.0.255&lt;BR /&gt;access-list 108 remark CCP_ACL Category=0&lt;BR /&gt;access-list 108 permit ip 10.10.11.0 0.0.0.255 10.10.10.0 0.0.0.255&lt;BR /&gt;access-list 109 remark CCP_ACL Category=0&lt;BR /&gt;access-list 109 permit ip 10.10.11.0 0.0.0.255 10.10.10.0 0.0.0.255&lt;BR /&gt;access-list 120 remark CCP_ACL Category=18&lt;BR /&gt;access-list 120 deny&amp;nbsp;&amp;nbsp; ip 10.10.10.0 0.0.0.255 10.10.50.0 0.0.0.255&lt;BR /&gt;access-list 120 deny&amp;nbsp;&amp;nbsp; ip 10.10.20.0 0.0.0.255 10.10.50.0 0.0.0.255&lt;BR /&gt;access-list 120 deny&amp;nbsp;&amp;nbsp; ip 10.10.10.0 0.0.0.255 10.10.11.0 0.0.0.255&lt;BR /&gt;access-list 120 permit ip 10.10.20.0 0.0.0.255 any&lt;BR /&gt;access-list 120 permit ip 10.10.10.0 0.0.0.255 any&lt;BR /&gt;access-list 121 permit ip 10.10.50.0 0.0.0.255 10.10.10.0 0.0.0.255&lt;BR /&gt;access-list 121 permit ip 10.10.50.0 0.0.0.255 10.10.20.0 0.0.0.255&lt;BR /&gt;access-list 150 permit tcp any any eq 8081&lt;BR /&gt;access-list 190 permit ip any host 10.10.10.7&lt;BR /&gt;access-list 190 permit ip host 10.10.10.7 any&lt;BR /&gt;no cdp run&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;route-map SDM_RMAP_1 permit 1&lt;BR /&gt;&amp;nbsp;match ip address 120&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2015 11:56:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remove-smtp-fixup-cisco-881-cli-command/m-p/2692351#M190739</guid>
      <dc:creator>fundataca</dc:creator>
      <dc:date>2015-06-12T11:56:12Z</dc:date>
    </item>
    <item>
      <title>Hi,Have you checked that the</title>
      <link>https://community.cisco.com/t5/network-security/remove-smtp-fixup-cisco-881-cli-command/m-p/2692352#M190740</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Have you checked that the mail server is not configured to receive only 2meg from cloud services?&lt;/P&gt;&lt;P&gt;Is the mail server 192.168.1.111 or 10.10.10.5?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can try editing the following policy map as a test to disable smtp fixup for outside to inside zone:&lt;/P&gt;&lt;P&gt;policy-map type inspect sdm-pol-NATOutsideToInside-1&lt;/P&gt;&lt;P&gt;&amp;nbsp;no class type inspect sdm-nat-smtp-1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2015 01:36:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remove-smtp-fixup-cisco-881-cli-command/m-p/2692352#M190740</guid>
      <dc:creator>johnd2310</dc:creator>
      <dc:date>2015-06-15T01:36:11Z</dc:date>
    </item>
  </channel>
</rss>

