<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ASA 5510, telnet to outside mx 587 doesn't work, no inspection for esmtp configured in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016089#M396556</link>
    <description>&lt;P&gt;Hi there&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't telnet from a host(Ubuntu 12.10) in our DMZ to an outside MX on port TCP 587. &lt;/P&gt;&lt;P&gt;Inspection for ESMTP not enabled. Port 587 enabled for host in DMZ to any.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone has an idea why ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 00:15:23 GMT</pubDate>
    <dc:creator>david.tannheimer</dc:creator>
    <dc:date>2019-03-12T00:15:23Z</dc:date>
    <item>
      <title>Cisco ASA 5510, telnet to outside mx 587 doesn't work, no inspection for esmtp configured</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016089#M396556</link>
      <description>&lt;P&gt;Hi there&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't telnet from a host(Ubuntu 12.10) in our DMZ to an outside MX on port TCP 587. &lt;/P&gt;&lt;P&gt;Inspection for ESMTP not enabled. Port 587 enabled for host in DMZ to any.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone has an idea why ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:15:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016089#M396556</guid>
      <dc:creator>david.tannheimer</dc:creator>
      <dc:date>2019-03-12T00:15:23Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA 5510, telnet to outside mx 587 doesn't work, no inspec</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016090#M396558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this situation your best bet is to&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Look at realtime log messages on ASDM using the source IP address as filter for example (And provide those logs here)&lt;/LI&gt;&lt;LI&gt;Capture traffic on the interface(s)&lt;/LI&gt;&lt;LI&gt;Do &lt;STRONG&gt;"packet-tracer"&lt;/STRONG&gt; for the traffic your trying to simulate (And provide the output here)&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;packet-tracer input &lt;INTERFACE name=""&gt; &lt;PROTOCOL&gt; &lt;SOURCE ip="" address=""&gt; &lt;SOURCE port=""&gt; &lt;DESTINATION ip="" address=""&gt; &lt;DESTINATION port=""&gt;&lt;/DESTINATION&gt;&lt;/DESTINATION&gt;&lt;/SOURCE&gt;&lt;/SOURCE&gt;&lt;/PROTOCOL&gt;&lt;/INTERFACE&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Oct 2012 09:33:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016090#M396558</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-10-29T09:33:40Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA 5510, telnet to outside mx 587 doesn't work, no inspec</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016091#M396560</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Realtime logs don't show anything.(Debugging mode)&lt;/P&gt;&lt;P&gt;- Packet-tracert shows packet is allowed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But i don't get through.&amp;nbsp; If I telnet to port 465, that works without problems, but 587 doesn't work. &lt;/P&gt;&lt;P&gt;If i do a telnet on another internetline where the firewall isn't an ASA, the telnet to Port 587 works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could it be that the inspection of WAAS traffic (Port 1-65536) is blocking it ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there something special with ASA and Telnet (from Windows and Linux) ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Oct 2012 15:16:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016091#M396560</guid>
      <dc:creator>david.tannheimer</dc:creator>
      <dc:date>2012-10-29T15:16:23Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA 5510, telnet to outside mx 587 doesn't work, no inspec</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016092#M396562</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello David,&lt;/P&gt;&lt;P&gt;Is there something special with ASA and Telnet (from Windows and Linux) ? Not at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would recommend you to run a capture&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;capture capout&amp;nbsp; interface outside match tcp host outside_ip&amp;nbsp; host public_mx_server_ip&lt;/P&gt;&lt;P&gt;capture capin interface inside match tcp host outside_ip host private_mx_server_ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now try to connect and then check what happens with the data being exchanged?&lt;/P&gt;&lt;P&gt;show cap capin&lt;/P&gt;&lt;P&gt;show cap capout &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you see the same packets on both interface ( same amount of packets,etc) &lt;/P&gt;&lt;P&gt;Does the 3 way handshake ocurs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Oct 2012 16:46:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016092#M396562</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-10-29T16:46:07Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA 5510, telnet to outside mx 587 doesn't work, no inspec</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016093#M396564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if u see packet going out from the firewall , then do a "netstat" under cmd and check wheather 587 is open or not or if anyone else is able to establish on 587 port with that pc.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Oct 2012 09:05:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016093#M396564</guid>
      <dc:creator>Riyasat Ali</dc:creator>
      <dc:date>2012-10-30T09:05:18Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA 5510, telnet to outside mx 587 doesn't work, no inspec</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016094#M396566</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Julio&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did a capture. On the Ingress i did see the traffic, but on the engress i did not see any traffic.&lt;/P&gt;&lt;P&gt;I will ask now the provider if they block that port. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Oct 2012 14:46:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016094#M396566</guid>
      <dc:creator>david.tannheimer</dc:creator>
      <dc:date>2012-10-30T14:46:46Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA 5510, telnet to outside mx 587 doesn't work, no inspec</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016095#M396568</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you mean by:&lt;/P&gt;&lt;P&gt;I did a capture. On the Ingress i did see the traffic, but on the engress i did not see any traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you mean you see the traffic on the outside interface but not on the Inside interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Oct 2012 17:09:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016095#M396568</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-10-30T17:09:54Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA 5510, telnet to outside mx 587 doesn't work, no inspec</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016096#M396569</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Julio&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did a capture with ASDM according to the following link:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080a9edd6.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080a9edd6.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes on the ingress the captured traffice is below and on the egress the packet capturing didn't show any&lt;/P&gt;&lt;P&gt;traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The capture below shows that a connection to port 465 works, but to port 587 it doesn't.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below the capture&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;18 packets captured&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 1: 07:55:59.208958 192.168.221.71.33194 &amp;gt; 80.74.140.62.465: S 3173494280:3173494280(0) win 14600 &lt;MSS 1460=""&gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp; 2: 07:55:59.211979 80.74.140.62.465 &amp;gt; 192.168.221.71.33194: S 2298408664:2298408664(0) ack 3173494281 win 5792 &lt;MSS 1380=""&gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp; 3: 07:55:59.212131 192.168.221.71.33194 &amp;gt; 80.74.140.62.465: . ack 2298408665 win 115 &lt;NOP&gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp; 4: 07:56:01.583984 192.168.221.71.33194 &amp;gt; 80.74.140.62.465: P 3173494281:3173494287(6) ack 2298408665 win 115 &lt;NOP&gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp; 5: 07:56:01.586532 80.74.140.62.465 &amp;gt; 192.168.221.71.33194: . ack 3173494287 win 5792 &lt;NOP&gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp; 6: 07:56:01.712975 192.168.221.71.33194 &amp;gt; 80.74.140.62.465: P 3173494287:3173494289(2) ack 2298408665 win 115 &lt;NOP&gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp; 7: 07:56:01.715508 80.74.140.62.465 &amp;gt; 192.168.221.71.33194: . ack 3173494289 win 5792 &lt;NOP&gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp; 8: 07:56:01.853532 192.168.221.71.33194 &amp;gt; 80.74.140.62.465: P 3173494289:3173494291(2) ack 2298408665 win 115 &lt;NOP&gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp; 9: 07:56:01.856126 80.74.140.62.465 &amp;gt; 192.168.221.71.33194: . ack 3173494291 win 5792 &lt;NOP&gt; &lt;BR /&gt;&amp;nbsp; 10: 07:56:04.375209 192.168.221.71.33194 &amp;gt; 80.74.140.62.465: P 3173494291:3173494297(6) ack 2298408665 win 115 &lt;NOP&gt; &lt;BR /&gt;&amp;nbsp; 11: 07:56:04.377727 80.74.140.62.465 &amp;gt; 192.168.221.71.33194: . ack 3173494297 win 5792 &lt;NOP&gt; &lt;BR /&gt;&amp;nbsp; 12: 07:56:04.379802 80.74.140.62.465 &amp;gt; 192.168.221.71.33194: P 2298408665:2298408770(105) ack 3173494297 win 5792 &lt;NOP&gt; &lt;BR /&gt;&amp;nbsp; 13: 07:56:04.379969 80.74.140.62.465 &amp;gt; 192.168.221.71.33194: R 2298408770:2298408770(0) ack 3173494297 win 5792 &lt;NOP&gt; &lt;BR /&gt;&amp;nbsp; 14: 07:56:04.380000 192.168.221.71.33194 &amp;gt; 80.74.140.62.465: . ack 2298408770 win 115 &lt;NOP&gt; &lt;BR /&gt;&amp;nbsp; 15: 07:56:07.052716 192.168.221.71.42608 &amp;gt; 80.74.140.62.587: S 793019550:793019550(0) win 14600 &lt;MSS 1460=""&gt; &lt;BR /&gt;&amp;nbsp; 16: 07:56:08.049100 192.168.221.71.42608 &amp;gt; 80.74.140.62.587: S 793019550:793019550(0) win 14600 &lt;MSS 1460=""&gt; &lt;BR /&gt;&amp;nbsp; 17: 07:56:10.053204 192.168.221.71.42608 &amp;gt; 80.74.140.62.587: S 793019550:793019550(0) win 14600 &lt;MSS 1460=""&gt; &lt;BR /&gt;&amp;nbsp; 18: 07:56:14.061398 192.168.221.71.42608 &amp;gt; 80.74.140.62.587: S 793019550:793019550(0) win 14600 &lt;MSS 1460=""&gt; &lt;BR /&gt;18 packets shown&lt;/MSS&gt;&lt;/MSS&gt;&lt;/MSS&gt;&lt;/MSS&gt;&lt;/NOP&gt;&lt;/NOP&gt;&lt;/NOP&gt;&lt;/NOP&gt;&lt;/NOP&gt;&lt;/NOP&gt;&lt;/NOP&gt;&lt;/NOP&gt;&lt;/NOP&gt;&lt;/NOP&gt;&lt;/NOP&gt;&lt;/NOP&gt;&lt;/MSS&gt;&lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Oct 2012 07:06:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016096#M396569</guid>
      <dc:creator>david.tannheimer</dc:creator>
      <dc:date>2012-10-31T07:06:59Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA 5510, telnet to outside mx 587 doesn't work, no inspec</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016097#M396573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the Reset packet:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; 13: 07:56:04.379969 80.74.140.62.465 &amp;gt; 192.168.221.71.33194: &lt;STRONG&gt;R&lt;/STRONG&gt; 2298408770:2298408770(0) ack 3173494297 win 5792 &lt;NOP&gt; &lt;/NOP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looks like the host 80.74 is closing the connection!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Oct 2012 17:38:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016097#M396573</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-10-31T17:38:14Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA 5510, telnet to outside mx 587 doesn't work, no inspec</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016098#M396576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Julio&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes but the reset belongs to the telnet to Port 465 and that works. From Port 587 i don't even&lt;/P&gt;&lt;P&gt;get a reset. I'm in contact now with our provider who says that they don't block any port, but&lt;/P&gt;&lt;P&gt;also can't telnet to Port 587 from a router in front of the ASA, very strange. I will update the &lt;/P&gt;&lt;P&gt;post as soon as i have the resolution. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Nov 2012 05:50:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016098#M396576</guid>
      <dc:creator>david.tannheimer</dc:creator>
      <dc:date>2012-11-01T05:50:18Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA 5510, telnet to outside mx 587 doesn't work, no inspec</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016099#M396580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually looks like the server does not reply on that port, so it does not look like an ASA or ISP issue... We only see the SYN packet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The capture is confusing to be honest with you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do the following using the CLI!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;capture dmz interface dmz match tcp host 192.168.221.71 host 80.74.140.62 eq 587&lt;/P&gt;&lt;P&gt;capture out interface out match tcp host outside_ip_192.168 host 80.73.140.62 31 587&lt;/P&gt;&lt;P&gt;cap asp type asp-drop all circular-buffer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where outside_ip_192.168 is the global nat ip address the dmz subnet is using on the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After you create the traffic, try to connect and provide&lt;/P&gt;&lt;P&gt;sho cap dmz&lt;/P&gt;&lt;P&gt;sho cap out&lt;/P&gt;&lt;P&gt;sho cap asp | include 80.73.140.62.31&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will provide you the answer afterwards &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Nov 2012 06:09:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016099#M396580</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-11-01T06:09:21Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA 5510, telnet to outside mx 587 doesn't work, no inspec</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016100#M396583</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Together&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After doing more reasearch with our ISP and on port 587, it seems that the port is not really listening.&lt;/P&gt;&lt;P&gt;Earlier telnet tests to this port over other firewalls/internet lines have shown now with tcpview that the&lt;/P&gt;&lt;P&gt;virusscanner has redirected telnet sessions to port 465. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So no ASA issue at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks to all for the answers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2012 13:14:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016100#M396583</guid>
      <dc:creator>david.tannheimer</dc:creator>
      <dc:date>2012-11-07T13:14:48Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA 5510, telnet to outside mx 587 doesn't work, no inspec</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016101#M396588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad to know that I could help,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate all of the answers ( If you do not know how just go to the stars at the bottom of each reply and mark the&amp;nbsp; 5 stars ( 1 being a bad answer, 5 being a good answer)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also mark the question as answered as you are the only one able to do that,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2012 17:37:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-telnet-to-outside-mx-587-doesn-t-work-no/m-p/2016101#M396588</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-11-07T17:37:18Z</dc:date>
    </item>
  </channel>
</rss>

