<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Mail server NAT translation with smtp redirect in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/mail-server-nat-translation-with-smtp-redirect/m-p/1994773#M401809</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Matt,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I din't really understand your scenario. Please correct me if am wrong. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your incoming smtp requests alone needs to be pointed to the GWAVA smtp filter Appliance (10.10.10.1 which is translated from 2.2.2.1). But your outbound smtp request has to be pointed to your smtp server (10.10.10.2 which is translated to 2.2.2.2). But now your SMTP request which is going out also getting translated to 2.2.2.1 and getting bounced right?????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know i will suggest you some ideas????&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 22 Jul 2012 07:36:27 GMT</pubDate>
    <dc:creator>nkarthikeyan</dc:creator>
    <dc:date>2012-07-22T07:36:27Z</dc:date>
    <item>
      <title>Mail server NAT translation with smtp redirect</title>
      <link>https://community.cisco.com/t5/network-security/mail-server-nat-translation-with-smtp-redirect/m-p/1994771#M401807</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are setting up a GWAVA smtp filter (IP address: 10.10.10.1)&amp;nbsp; appliance that needs incoming smtp traffic redirected to it.&amp;nbsp; I still need the mail server (IP address 10.10.10.2)&amp;nbsp;&amp;nbsp; to have a 1 to 1 nat translation to an outside IP address&amp;nbsp; (IP address 2.2.2.2).&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The way I have it setup now, smtp traffic is being redirected to our GWAVA filter , and outside users can still connect their email clients to the internal mail server.&amp;nbsp; However, outbound mail being generating by our email server is being sent out a different external IP (2.2.2.1) causing some emails to get returned because they don't match the mx records.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems simple enough, but when I create a static NAT rule mapping 10.10.10.2 to the outside IP 2.2.2.2, it seems to overule the smtp redirect rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could someone give me a set of simple commands to add these rules?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:33:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mail-server-nat-translation-with-smtp-redirect/m-p/1994771#M401807</guid>
      <dc:creator>mhobart</dc:creator>
      <dc:date>2019-03-11T23:33:04Z</dc:date>
    </item>
    <item>
      <title>Mail server NAT translation with smtp redirect</title>
      <link>https://community.cisco.com/t5/network-security/mail-server-nat-translation-with-smtp-redirect/m-p/1994772#M401808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bro&lt;/P&gt;&lt;P&gt;Your setup isn't unique. There are many clients out there that has this similar setup running. Hence, this should be easy to resolve. Are you able to paste your latest show running-config here, so that I can advice you accordingly what needs to be added/remove etc.?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jul 2012 18:28:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mail-server-nat-translation-with-smtp-redirect/m-p/1994772#M401808</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2012-07-20T18:28:15Z</dc:date>
    </item>
    <item>
      <title>Mail server NAT translation with smtp redirect</title>
      <link>https://community.cisco.com/t5/network-security/mail-server-nat-translation-with-smtp-redirect/m-p/1994773#M401809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Matt,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I din't really understand your scenario. Please correct me if am wrong. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your incoming smtp requests alone needs to be pointed to the GWAVA smtp filter Appliance (10.10.10.1 which is translated from 2.2.2.1). But your outbound smtp request has to be pointed to your smtp server (10.10.10.2 which is translated to 2.2.2.2). But now your SMTP request which is going out also getting translated to 2.2.2.1 and getting bounced right?????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know i will suggest you some ideas????&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Jul 2012 07:36:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mail-server-nat-translation-with-smtp-redirect/m-p/1994773#M401809</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2012-07-22T07:36:27Z</dc:date>
    </item>
    <item>
      <title>Mail server NAT translation with smtp redirect</title>
      <link>https://community.cisco.com/t5/network-security/mail-server-nat-translation-with-smtp-redirect/m-p/1994774#M401810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Sorry for the delay,&amp;nbsp; I got the smtp redirect working along with the outgoing mail being mapped correctly.&amp;nbsp; However, I have a new issue now,&amp;nbsp; I posted parts of my sh run output below. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe the issue I need to figure out is called "Hairpinning" but I"m not sure.&amp;nbsp; I'm running ASA 8.3 by the way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue is, the GWAVA filter sends out digests where users can click on a link to release any quarantined mail.&amp;nbsp; The link can be edited, but right now it uses the internal ip address of the GWAVA filter (10.10.10.1) so interally the link works perfectly.&amp;nbsp; However, on the public side the link doesn't work obviously because it it can't see 10.10.10.1.&amp;nbsp; So I wanted to put in the public IP of the mail server 2.2.2.2 and just have the ASA redirect the port 49285 to the internal GWAVA appliance (10.10.10.1)&amp;nbsp; Now this works perfectly on the outside and the redirect for port 49285 is working, but it doesn't work on the inside because users can't see the external IP of the GWSRV mail server 2.2.2.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everything I've read seems to point to hairpinning, but I can't seem to get the right configuration.&amp;nbsp; I just need internal requests for 2.2.2.2 on port 49285 to be directed to the GWAVA internal IP 10.10.10.1 so the "Release" link in those emails will works both on the public and private side of the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also have a cisco 3560 l3 swith in place on the network that all hosts use as their default gateway.&amp;nbsp; The default gateway of that switch is the ASA device.&amp;nbsp; So I'm not sure if that's interfering either.&amp;nbsp; We have an internal dns server 10.10.10.4 that resolves the mail server domain name to its internal ip 10.10.10.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface GigabitEthernet0/0&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; nameif inside&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; security-level 100&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; ip address 10.10.10.3 255.0.0.0&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;!&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;interface GigabitEthernet0/3&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; speed 100&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; duplex full&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; nameif outside&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; security-level 100&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; ip address 2.2.2.1 255.255.255.224&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;dns domain-lookup inside&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;dns server-group DefaultDNS&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; name-server 10.10.10.4&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;same-security-traffic permit inter-interface&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;same-security-traffic permit intra-interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;object service GWClient&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; service tcp destination eq 1677&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;object network GWAVA&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; host 10.10.10.1&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;object network GWSRV&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; host 10.10.10.2&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;object service GWWEB&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; service tcp destination eq www&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;object service QMS&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; service tcp destination eq 49285&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;object-group protocol TCPUDP&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; protocol-object udp&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; protocol-object tcp&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;object-group network obj_any&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; service-object object GWClient&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; service-object object GWWEB&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; service-object object QMS&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; service-object object SMTP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list outside_in extended permit object-group DM_INLINE_SERVICE_2 any host&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; 10.10.10.1&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;access-list outside_in extended permit object-group DM_INLINE_SERVICE_1 any host&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; 10.10.10.2&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;access-list outside_in extended deny ip any any&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list inside_access_in extended permit ip object 10.0.0.0 any&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;access-list inside_access_in extended deny ip any any&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (outside,inside) source static any any destination static A_2.2.2.2 GWAVA service SMTP SMTP unidirectional&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;nat (outside,inside) source static any any destination static A_2.2.2.2 GWAVA service QMS QMS unidirectional&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;nat (outside,any) source static any any destination static A_2.2.2.2 GWSRV service GWClient GWClient unidirectional&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;nat (outside,any) source static any any destination static A_2.2.2.2 GWSRV service GWWEB GWWEB unidirectional&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;nat (inside,outside) source static GWSRV A_2.2.2.2 unidirectional&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;!&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;object network 10.0.0.0&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; nat (inside,outside) dynamic interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-group inside_access_in in interface inside&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;access-group outside_in in interface outside&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;route outside 0.0.0.0 0.0.0.0 2.2.2.3 1&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Jul 2012 15:32:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mail-server-nat-translation-with-smtp-redirect/m-p/1994774#M401810</guid>
      <dc:creator>mhobart</dc:creator>
      <dc:date>2012-07-22T15:32:27Z</dc:date>
    </item>
    <item>
      <title>Mail server NAT translation with smtp redirect</title>
      <link>https://community.cisco.com/t5/network-security/mail-server-nat-translation-with-smtp-redirect/m-p/1994775#M401811</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Matt,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand your concern. So you need to do NAT from outside to inside using general NAT. And NAT hairpinning concept to use when it is in local from the LAN. It should take the local address instead of public. So that it will go through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes.If the you should have the follwing command enabled for this reverse turn for local requests.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface. This will make the traffic to in and out on the same interface. &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;static (inside,outside) 2.2.2.2 10.10.10.1&lt;/P&gt;&lt;P&gt;static (inside,inside) 2.2.2.2 10.10.10.1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make some alterations as per your 8.3 version commands. Still i have not used to that one. &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/wink.gif"&gt;&lt;/SPAN&gt;. But this is the concept. When the request comes for LAN network of the inside network it translates to 10.10.10.1 and goes locally using intra interface. When it comes from outside it will go through the static nat from public to private.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do rate if the given information helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Jul 2012 16:40:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mail-server-nat-translation-with-smtp-redirect/m-p/1994775#M401811</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2012-07-22T16:40:38Z</dc:date>
    </item>
    <item>
      <title>Mail server NAT translation with smtp redirect</title>
      <link>https://community.cisco.com/t5/network-security/mail-server-nat-translation-with-smtp-redirect/m-p/1994776#M401812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bro&lt;/P&gt;&lt;P&gt;In order to allow your INSIDE users to see the external IP of the GWSRV mail server, you'll need to configure DNS Doctoring, to resolve this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network obj-10.10.10.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; host 10.10.10.1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (inside,outside) static 2.2.2.2 dns&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For further details, you could refer to &lt;A _jive_internal="true" href="https://community.cisco.com/thread/2035927"&gt;https://supportforums.cisco.com/thread/2035927&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P/S: If you think this comment is useful, please do rate them nicely &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Jul 2012 16:53:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mail-server-nat-translation-with-smtp-redirect/m-p/1994776#M401812</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2012-07-22T16:53:34Z</dc:date>
    </item>
  </channel>
</rss>

