<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 8.4x ESMTP Inspection bug CSCtr92976? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-8-4x-esmtp-inspection-bug-csctr92976/m-p/1965127#M400966</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It quite blatantly just doesn't work.&amp;nbsp; I am reluctant to downgrade to 8.2 or earlier because of the NAT issues I will inevitably hit.&amp;nbsp; I'll try 8.3 on the lab 5505 and see how this behaves - I suspect it will be the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can Cisco get away with not fixing this if its been around since PIX days?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 10 Aug 2012 22:48:14 GMT</pubDate>
    <dc:creator>andrew.butterworth</dc:creator>
    <dc:date>2012-08-10T22:48:14Z</dc:date>
    <item>
      <title>ASA 8.4x ESMTP Inspection bug CSCtr92976?</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4x-esmtp-inspection-bug-csctr92976/m-p/1965125#M400964</link>
      <description>&lt;P&gt;We have several customers running ASA 8.4x code and all seem to be plagued with the ESMTP inspection bug CSCtr92976.&lt;/P&gt;&lt;P&gt;I have tested this in the lab with an ASA 5505 running 8.4(1), 8.4(2) and 8.4(4)1 &amp;amp; 8.4(4)3 and the behaviour is always the same.&amp;nbsp; I have an Exchange 2007 server and I can see in the logs the following messages:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2012-08-10T13:04:37.331Z,EXCHANGE\Default EXCHANGE,08CF3610468A42D7,3,192.168.102.28:25,192.168.250.26:52756,&amp;lt;,XXXX XXXXXXXXXXXXXXX,&lt;/P&gt;&lt;P&gt;2012-08-10T13:04:42.345Z,EXCHANGE\Default EXCHANGE,08CF3610468A42D7,4,192.168.102.28:25,192.168.250.26:52756,&amp;gt;,500 5.3.3 Unrecognized command,&lt;/P&gt;&lt;P&gt;2012-08-10T13:05:20.506Z,EXCHANGE\Default EXCHANGE,08CF3610468A42D7,5,192.168.102.28:25,192.168.250.26:52756,&amp;lt;,XXX,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is with the default ESMTP inspection enabled.&amp;nbsp; I have also created a custom ESMTP inspection policy that does nothing but log and the behaviour is still the same.&amp;nbsp; Sometimes traffic will pass but most of the time it won't.&amp;nbsp; The workaround is to just disable the ESMTP inspection but I don't like the idea of this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea when this will be fixed or if there is some other magic workaround?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:40:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4x-esmtp-inspection-bug-csctr92976/m-p/1965125#M400964</guid>
      <dc:creator>andrew.butterworth</dc:creator>
      <dc:date>2019-03-11T23:40:53Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4x ESMTP Inspection bug CSCtr92976?</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4x-esmtp-inspection-bug-csctr92976/m-p/1965126#M400965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Will it ever be? The ESMTP-inspection is somehow the successor of the "Mailguard". And that was the worst function for nearly every mail-administrator in the past with PIX firewalls on the network ...&lt;/P&gt;&lt;P&gt;It got better with the ESMTP-inspection, but I assume the troble will never end. I typically disable it. The mailserver is protected by the mail-relay in the DMZ and the mail-relay has to protect himself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Aug 2012 19:06:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4x-esmtp-inspection-bug-csctr92976/m-p/1965126#M400965</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2012-08-10T19:06:18Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4x ESMTP Inspection bug CSCtr92976?</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4x-esmtp-inspection-bug-csctr92976/m-p/1965127#M400966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It quite blatantly just doesn't work.&amp;nbsp; I am reluctant to downgrade to 8.2 or earlier because of the NAT issues I will inevitably hit.&amp;nbsp; I'll try 8.3 on the lab 5505 and see how this behaves - I suspect it will be the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can Cisco get away with not fixing this if its been around since PIX days?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Aug 2012 22:48:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4x-esmtp-inspection-bug-csctr92976/m-p/1965127#M400966</guid>
      <dc:creator>andrew.butterworth</dc:creator>
      <dc:date>2012-08-10T22:48:14Z</dc:date>
    </item>
  </channel>
</rss>

