<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exchange 2000 behind ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/exchange-2000-behind-asa/m-p/590298#M423533</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes thats enabled,&lt;/P&gt;&lt;P&gt;LAN and WAN interfaces can communicate without any problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your reply&lt;/P&gt;&lt;P&gt;Muhammad &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 04 Sep 2006 05:14:11 GMT</pubDate>
    <dc:creator>msubtain</dc:creator>
    <dc:date>2006-09-04T05:14:11Z</dc:date>
    <item>
      <title>Exchange 2000 behind ASA</title>
      <link>https://community.cisco.com/t5/network-security/exchange-2000-behind-asa/m-p/590296#M423531</link>
      <description>&lt;P&gt;I am running ASA 5510 in with 3 interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;E0/0 INTENET (Security Level 0)&lt;/P&gt;&lt;P&gt;E0/1 WAN (Security Level 100)&lt;/P&gt;&lt;P&gt;E0/2 LAN (Security Level 100)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using NAT for internet on LAN interface, no outgoing ACL, and nothing is open in terms of incoming. LAN and WAN interfaces are also NATTED to same addresses in order to talk to each other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everything works fine, except the exchange server sitting on LAN interface which handles the outgoing emails for the local users and is connected over the WAN to our Front end server sitting in one of our branch office.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Exchange server does send outgoing emails sometimes and sometimes it generates NDR and send back to sender, stating "UNABLE TO RELAY", &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nothing is bloced in terms of outgoing from higher security interface(LAN) to Lower security interface (Internet) which is default behaviour of ASA. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone put some light on it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Muhammad&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:09:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/exchange-2000-behind-asa/m-p/590296#M423531</guid>
      <dc:creator>msubtain</dc:creator>
      <dc:date>2020-02-21T09:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: Exchange 2000 behind ASA</title>
      <link>https://community.cisco.com/t5/network-security/exchange-2000-behind-asa/m-p/590297#M423532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ..  are you saying that the exchage server which is located behing the LAN interface needs to communicate with the 'front end server'  which is located behind the WAN interface ..?  If that is the case have you check that the command   same-security-traffic permit inter-interface  is enabled on your config  ..?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Sep 2006 05:06:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/exchange-2000-behind-asa/m-p/590297#M423532</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2006-09-04T05:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: Exchange 2000 behind ASA</title>
      <link>https://community.cisco.com/t5/network-security/exchange-2000-behind-asa/m-p/590298#M423533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes thats enabled,&lt;/P&gt;&lt;P&gt;LAN and WAN interfaces can communicate without any problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your reply&lt;/P&gt;&lt;P&gt;Muhammad &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Sep 2006 05:14:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/exchange-2000-behind-asa/m-p/590298#M423533</guid>
      <dc:creator>msubtain</dc:creator>
      <dc:date>2006-09-04T05:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: Exchange 2000 behind ASA</title>
      <link>https://community.cisco.com/t5/network-security/exchange-2000-behind-asa/m-p/590299#M423534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the mail server is able to send mail sometimes properly, then there shouldn't be any issue in the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you check whether the connectivity to the front-end-server from the exchange server is working fine.&lt;/P&gt;&lt;P&gt;Is the wan connectivity stable with enough bandwidth?&lt;/P&gt;&lt;P&gt;You can do some monitoring on the connectivity to the front-end-server, by using icmp polling..etc and see if the connectivity is stable to rule out any possible problem &lt;/P&gt;&lt;P&gt;enroute to the front-end-server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.. Rate replies if found useful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-VJ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Sep 2006 10:29:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/exchange-2000-behind-asa/m-p/590299#M423534</guid>
      <dc:creator>vijayasankar</dc:creator>
      <dc:date>2006-09-05T10:29:06Z</dc:date>
    </item>
  </channel>
</rss>

