<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ESMTP connection dropped in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/esmtp-connection-dropped/m-p/2227989#M348883</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You probably have a configuration similiar to this under some "policy-map" configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; match cmd RCPT count gt 100&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; drop-connection log&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I would imagine you would have to increase the amount if that is the requirement&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 31 May 2013 09:16:20 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-05-31T09:16:20Z</dc:date>
    <item>
      <title>ESMTP connection dropped</title>
      <link>https://community.cisco.com/t5/network-security/esmtp-connection-dropped/m-p/2227987#M348881</link>
      <description>&lt;P&gt;hello,&lt;/P&gt;&lt;P&gt;We are working with an ASA 5520 and it seems there is an issue with some email messages sent throught it.&lt;/P&gt;&lt;P&gt;When there are many recipients in the emails the email messages are not sent, and I have revised the server an the only thing I see is connecting dropped.&lt;/P&gt;&lt;P&gt;When I went to see ASA log and see this log report: &lt;/P&gt;&lt;P&gt;ESMTP Classification: Dropped connection for ESMTP Request from 'interface': servername/portnumber to outside: IP address/25; matched Class 2: cmd RCPT count gt 100&lt;/P&gt;&lt;P&gt;tcp flow from interface:servername/portnumber to outside: IP address/25 terminated by inspection engine, reason - inspector disconnected, dropped packet.&lt;/P&gt;&lt;P&gt;So I think there should be an inspection of ESMTP packets and if they detect an email message sent to over 100 addresses, then the packet is dropped, am I right? if so, what should I do to let those email messages be sent?&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:51:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/esmtp-connection-dropped/m-p/2227987#M348881</guid>
      <dc:creator>david.fernandez.fernandez</dc:creator>
      <dc:date>2019-03-12T01:51:36Z</dc:date>
    </item>
    <item>
      <title>ESMTP connection dropped</title>
      <link>https://community.cisco.com/t5/network-security/esmtp-connection-dropped/m-p/2227988#M348882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the CLI these rules are configured with the policy-maps. There you find a rule where these limits are enforced and where you can change the limits or even disable the checks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Probably there is a reason that someone configured these policies as they are not a default-config. So you have to decide how your new policy should be and if you post the relevant part of the config, we can assist you in changing the parameters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 May 2013 09:13:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/esmtp-connection-dropped/m-p/2227988#M348882</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-05-31T09:13:01Z</dc:date>
    </item>
    <item>
      <title>ESMTP connection dropped</title>
      <link>https://community.cisco.com/t5/network-security/esmtp-connection-dropped/m-p/2227989#M348883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You probably have a configuration similiar to this under some "policy-map" configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; match cmd RCPT count gt 100&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; drop-connection log&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I would imagine you would have to increase the amount if that is the requirement&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 May 2013 09:16:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/esmtp-connection-dropped/m-p/2227989#M348883</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-05-31T09:16:20Z</dc:date>
    </item>
    <item>
      <title>ESMTP connection dropped</title>
      <link>https://community.cisco.com/t5/network-security/esmtp-connection-dropped/m-p/2227990#M348884</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;thank you for your answers. &lt;/P&gt;&lt;P&gt;I have checked the running-config and I did not found the parameters, but I leave that configuration part here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map global-class&lt;/P&gt;&lt;P&gt; match access-list global_mpc_5&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&amp;lt;--- More ---&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map type inspect im impolicy&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt; match protocol msn-im yahoo-im &lt;/P&gt;&lt;P&gt;&amp;nbsp; drop-connection&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225 &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp &lt;/P&gt;&lt;P&gt;&amp;lt;--- More ---&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options &lt;/P&gt;&lt;P&gt; class global-class&lt;/P&gt;&lt;P&gt;&amp;nbsp; csc fail-close&lt;/P&gt;&lt;P&gt;policy-map type inspect http P2P_HTTP&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt; match request uri regex _default_gator&lt;/P&gt;&lt;P&gt; match request uri regex _default_x-kazaa-network&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop-connection log&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;smtp-server 10.0.1.31 10.0.1.34&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much&lt;/P&gt;&lt;P&gt;best regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 May 2013 10:17:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/esmtp-connection-dropped/m-p/2227990#M348884</guid>
      <dc:creator>david.fernandez.fernandez</dc:creator>
      <dc:date>2013-05-31T10:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: ESMTP connection dropped</title>
      <link>https://community.cisco.com/t5/network-security/esmtp-connection-dropped/m-p/2227991#M348885</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if its some default limt value then. To be honest I havent had to change these configurations that much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would imagine that the limit could be raised with a configuration. The value naturally depends on you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;policy-map type inspect esmtp ESMTP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; match cmd RCPT count gt 200 &lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; drop-connection log&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;policy-map global_policy&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; class inspection_default&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; inspect esmtp ESMTP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; But I have to say I am not sure if that is all that you need. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would have to first remove the existing "inspect esmtp" which might affect some traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 May 2013 10:28:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/esmtp-connection-dropped/m-p/2227991#M348885</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-05-31T10:28:23Z</dc:date>
    </item>
    <item>
      <title>Re: ESMTP connection dropped</title>
      <link>https://community.cisco.com/t5/network-security/esmtp-connection-dropped/m-p/2227992#M348886</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just looked it up and there is (also to my suprise) a default for this parameter. The complete defaults for ESMTP are these values:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;policy-map type inspect esmtp _default_esmtp_map&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; description Default ESMTP policy-map&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; parameters&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; mask-banner&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; no mail-relay&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; no special-character&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; no allow-tls&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; match cmd line length gt 512&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; drop-connection log&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt; match cmd RCPT count gt 100&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; drop-connection log&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; match body line length gt 998&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; log&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; match header line length gt 998&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; drop-connection log&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; match sender-address length gt 320&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; drop-connection log&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; match MIME filename length gt 255&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; drop-connection log&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; match ehlo-reply-parameter others&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp; mask&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To solve that problem you could disable the whole ESMTP-inspection or overwrite the parameter in question as by Jounis direction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni" rel="nofollow"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 May 2013 11:52:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/esmtp-connection-dropped/m-p/2227992#M348886</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-05-31T11:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: ESMTP connection dropped</title>
      <link>https://community.cisco.com/t5/network-security/esmtp-connection-dropped/m-p/2227993#M348887</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; ok,&lt;/P&gt;&lt;P&gt;I have finally gone to default configuration and disable inspect for ESMTP traffic.&lt;/P&gt;&lt;P&gt;Now I see no ESMTP being log or dropped in the ASA log.&lt;/P&gt;&lt;P&gt;I will now see if the email the several recipients works as it should.&lt;/P&gt;&lt;P&gt;thank you both a lot.&lt;/P&gt;&lt;P&gt;best regards.&lt;/P&gt;&lt;P&gt;David.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 May 2013 12:23:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/esmtp-connection-dropped/m-p/2227993#M348887</guid>
      <dc:creator>david.fernandez.fernandez</dc:creator>
      <dc:date>2013-05-31T12:23:26Z</dc:date>
    </item>
  </channel>
</rss>

