<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem sending mails thought ASA 5505 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-sending-mails-thought-asa-5505/m-p/1911812#M457698</link>
    <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 subnets bought from my provider 194.102.98.128/27 and 194.102.98.160/27. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From my provider a have the following setup:&lt;/P&gt;&lt;PRE&gt;IP Address:&amp;nbsp; 86.120.151.66
Netmask:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.128
Gateway:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 86.120.151.1
DNS (1): 213.154.124.1
DNS (2): 193.231.252.1&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My IPs are static routed by my provider thought 86.120.151.66 . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the firewall I have the following set-up: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Outside Interface: 86.120.151.66/25 security level 0&lt;/P&gt;&lt;P&gt;DMZ interface: 194.102.98.129/27 security level 50&lt;/P&gt;&lt;P&gt;Inside Interface: 194.102.98.161/27 security level 100&lt;/P&gt;&lt;P&gt;0.0.0.0 0.0.0.0 [1/0] via 86.120.151.1, outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everything works perfectly except when I try to sent an email. The email gets sent (eventually), but afert a long waiting time, 45-60 sec. The connection is opened instally to the server but then just hangs there for 40-50 sec. The problem is that a have an aplication on a server that has to send confirmation emails, and that aplication is limited to a 30 sec timeout for conecting to the mail server, much less then the 45-60 sec that I have now. The mail server is hosted by a data center, it is not in my networks (location).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried deleting the ESMTP inspection, that doesn't work. Pinging my mail server rezults in a average time of 20 ms. And when a do a tracert the hight value in a&amp;nbsp; hop doesn't usually pass 80 ms, the average is 20-25 ms. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is ONLY when sending emails. Everything else works perfect, including receiving emails from the same server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My running config is: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname ASA-Adisys&lt;/P&gt;&lt;P&gt;domain-name Intern.ro&lt;/P&gt;&lt;P&gt;enable password 0./39zRW9yhKK/bO encrypted&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 91.220.232.66 &lt;A href="https://community.cisco.com/www.itarena.ro" target="_blank"&gt;www.itarena.ro&lt;/A&gt; description Adresa IP a site-ului&lt;/P&gt;&lt;P&gt;name 194.102.98.161 Inside_Gateway&lt;/P&gt;&lt;P&gt;name 172.16.10.96 VPN_Adress_POOL&lt;/P&gt;&lt;P&gt;name 194.102.98.185 Adisys_Cara&lt;/P&gt;&lt;P&gt;name 194.102.98.165 Adisys_Cyclope&lt;/P&gt;&lt;P&gt;name 194.102.98.184 Adisys_UC540W description Adresa de WAN Adisys&lt;/P&gt;&lt;P&gt;name 194.102.98.133 DMZ_Agnor_IP1&lt;/P&gt;&lt;P&gt;name 194.102.98.134 DMZ_Agnor_IP2&lt;/P&gt;&lt;P&gt;name 194.102.98.146 DMZ_Fasttrack&lt;/P&gt;&lt;P&gt;name 194.102.98.150 DMZ_Graitec_Auth_Server&lt;/P&gt;&lt;P&gt;name 194.102.98.148 DMZ_Graitec_Axapta&lt;/P&gt;&lt;P&gt;name 194.102.98.149 DMZ_Graitec_Citrix&lt;/P&gt;&lt;P&gt;name 194.102.98.147 DMZ_Graitec_FTP&lt;/P&gt;&lt;P&gt;name 194.102.98.144 DMZ_Jeka&lt;/P&gt;&lt;P&gt;name 194.102.98.142 DMZ_Agras&lt;/P&gt;&lt;P&gt;name 194.102.98.132 DMZ_Router_Dlink description Adresa de la router-ul din spate&lt;/P&gt;&lt;P&gt;name 89.122.106.51 Graitec_Remote_PC1 description Calculator dupa care se face RDC Graitec&lt;/P&gt;&lt;P&gt;name 89.122.49.40 Graitec_Remote_PC3 description Calculator dupa care se face RDC Graitec&lt;/P&gt;&lt;P&gt;name 184.154.10.114 Graitec_mail.graitec.info&lt;/P&gt;&lt;P&gt;name 89.120.49.209 Graitec_mail.graitec.net description Calculator dupa care se face RDC Graitec&lt;/P&gt;&lt;P&gt;name 89.122.248.141 Graitec_mail.graitec.ro description Calculator dupa care se face RDC Graitec&lt;/P&gt;&lt;P&gt;name 81.80.156.221 Graitec_mailhost.graitec.com&lt;/P&gt;&lt;P&gt;name 82.137.9.82 Test_IP description IP de test&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address Inside_Gateway 255.255.255.224&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; description IP Internet&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 86.120.151.66 255.255.255.128&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan12&lt;/P&gt;&lt;P&gt; description Retea clienti&lt;/P&gt;&lt;P&gt; no forward interface Vlan1&lt;/P&gt;&lt;P&gt; nameif DMZ&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt; ip address 194.102.98.129 255.255.255.224&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt; switchport access vlan 12&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt; switchport access vlan 12&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone EEST 2&lt;/P&gt;&lt;P&gt;clock summer-time EEDT recurring last Sun Mar 3:00 last Sun Oct 4:00&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; domain-name Intern.ro&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_1&lt;/P&gt;&lt;P&gt; network-object host Graitec_mail.graitec.net&lt;/P&gt;&lt;P&gt; network-object host Graitec_Remote_PC1&lt;/P&gt;&lt;P&gt; network-object host Graitec_mail.graitec.ro&lt;/P&gt;&lt;P&gt; network-object host Graitec_Remote_PC3&lt;/P&gt;&lt;P&gt; network-object host Test_IP&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_2&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Axapta&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Citrix&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Auth_Server&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_3&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Axapta&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Citrix&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Auth_Server&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_4&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Citrix&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Auth_Server&lt;/P&gt;&lt;P&gt; network-object host Inside_Gateway&lt;/P&gt;&lt;P&gt; network-object host Adisys_UC540W&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_5&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Axapta&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Citrix&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Auth_Server&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_6&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Citrix&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Auth_Server&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_7&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Axapta&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Citrix&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Auth_Server&lt;/P&gt;&lt;P&gt;object-group protocol TCPUDP&lt;/P&gt;&lt;P&gt; protocol-object udp&lt;/P&gt;&lt;P&gt; protocol-object tcp&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_8&lt;/P&gt;&lt;P&gt; network-object host Inside_Gateway&lt;/P&gt;&lt;P&gt; network-object host Adisys_UC540W&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_10&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_FTP&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Axapta&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Citrix&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Auth_Server&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_9&lt;/P&gt;&lt;P&gt; network-object host Graitec_mail.graitec.info&lt;/P&gt;&lt;P&gt; network-object host Graitec_mailhost.graitec.com&lt;/P&gt;&lt;P&gt; network-object host Graitec_mail.graitec.net&lt;/P&gt;&lt;P&gt; network-object host Graitec_mail.graitec.ro&lt;/P&gt;&lt;P&gt; network-object host Graitec_Remote_PC3&lt;/P&gt;&lt;P&gt;object-group protocol DM_INLINE_PROTOCOL_1&lt;/P&gt;&lt;P&gt; protocol-object icmp&lt;/P&gt;&lt;P&gt; protocol-object icmp6&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_1 tcp&lt;/P&gt;&lt;P&gt; port-object eq 2525&lt;/P&gt;&lt;P&gt; port-object eq 465&lt;/P&gt;&lt;P&gt; port-object eq pop3&lt;/P&gt;&lt;P&gt; port-object eq smtp&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow access to Auth, Axapta, Citrix to 3389&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp object-group DM_INLINE_NETWORK_1 object-group DM_INLINE_NETWORK_2 eq 3389&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow access to Citrix, Auth, Adisys_WAN to port 443&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object-group DM_INLINE_NETWORK_4 eq https&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow access to Auth, Axapta, Citrix from port 80&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any eq www object-group DM_INLINE_NETWORK_3&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow access to Auth, Axapta, Citrix from port 53&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object-group TCPUDP any eq domain object-group DM_INLINE_NETWORK_5&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow access to Auth, Citrix from port 443&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any eq https object-group DM_INLINE_NETWORK_6&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp object-group DM_INLINE_NETWORK_9 object-group DM_INLINE_NETWORK_10 object-group DM_INLINE_TCP_1&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow Ping to graitec servers&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object-group DM_INLINE_PROTOCOL_1 any any&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Deny any to Axapta, Auth, Citrix&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended deny ip any object-group DM_INLINE_NETWORK_7&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow access to Adisys_WAN from Non500-isakmp&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit udp any host Adisys_UC540W eq 4500&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow access to Adisys_WAN from Isakmp&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit udp any object-group DM_INLINE_NETWORK_8 eq isakmp&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow access to Adisys_WAN from esp&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit esp any host Adisys_UC540W&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow access to Adisys_WAN from AHP&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ah any host Adisys_UC540W&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow syslog messeger from ITarena.ro to Cyclope Syslog&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit udp host &lt;A href="https://community.cisco.com/www.itarena.ro" target="_blank"&gt;www.itarena.ro&lt;/A&gt; host Adisys_Cyclope eq syslog&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow 113 from &lt;A href="http://www.itarena.ro" target="_blank"&gt;www.itarena.ro&lt;/A&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp host &lt;A href="https://community.cisco.com/www.itarena.ro" target="_blank"&gt;www.itarena.ro&lt;/A&gt; 194.102.98.160 255.255.255.224 eq ident&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow Mark Vision from internet&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host Adisys_UC540W eq 9788&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host DMZ_Router_Dlink eq www&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow TFTP for Voice&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip VPN_Adress_POOL 255.255.255.240 194.102.98.160 255.255.255.224 inactive&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow TFTP from inside to VPN&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip 194.102.98.160 255.255.255.224 VPN_Adress_POOL 255.255.255.240 inactive&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Deny any to Inside Network 194.102.98.160/27&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended deny ip any 194.102.98.160 255.255.255.224&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip any 194.102.98.128 255.255.255.224&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow Ping&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list THROTTLE_GRAITEC_FTP extended permit ip host DMZ_Graitec_FTP any&lt;/P&gt;&lt;P&gt;access-list THROTTLE_GRAITEC_FTP extended permit ip any host DMZ_Graitec_FTP&lt;/P&gt;&lt;P&gt;access-list Adisan-VPN_splitTunnelAcl standard permit 194.102.98.160 255.255.255.224&lt;/P&gt;&lt;P&gt;access-list outside_mpc extended permit ip host DMZ_Fasttrack any&lt;/P&gt;&lt;P&gt;access-list outside_mpc extended permit ip any host DMZ_Fasttrack&lt;/P&gt;&lt;P&gt;access-list outside_access_in_1 remark Allow&lt;/P&gt;&lt;P&gt;access-list outside_access_in_1 extended permit tcp any any eq https&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging trap warnings&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging host inside Adisys_UC540W&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;ip local pool VPN_POOL 172.16.10.97-172.16.10.110&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;access-group outside_access_in_1 in interface outside control-plane&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 86.120.151.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 194.102.98.160 255.255.255.224 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime seconds 28800&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;/P&gt;&lt;P&gt;crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside&lt;/P&gt;&lt;P&gt;crypto isakmp enable outside&lt;/P&gt;&lt;P&gt;crypto isakmp policy 5&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; encryption 3des&lt;/P&gt;&lt;P&gt; hash sha&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 86400&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; encryption des&lt;/P&gt;&lt;P&gt; hash sha&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 86400&lt;/P&gt;&lt;P&gt;crypto isakmp policy 30&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; encryption aes&lt;/P&gt;&lt;P&gt; hash sha&lt;/P&gt;&lt;P&gt; group 5&lt;/P&gt;&lt;P&gt; lifetime 86400&lt;/P&gt;&lt;P&gt;no vpn-addr-assign aaa&lt;/P&gt;&lt;P&gt;no vpn-addr-assign dhcp&lt;/P&gt;&lt;P&gt;telnet 194.102.98.160 255.255.255.224 inside&lt;/P&gt;&lt;P&gt;telnet timeout 15&lt;/P&gt;&lt;P&gt;ssh 194.102.98.160 255.255.255.224 inside&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address Adisys_Cyclope-194.102.98.170 inside&lt;/P&gt;&lt;P&gt;dhcpd dns 8.8.8.8 8.8.4.4 interface inside&lt;/P&gt;&lt;P&gt;dhcpd enable inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics&lt;/P&gt;&lt;P&gt;threat-detection statistics host number-of-rate 2&lt;/P&gt;&lt;P&gt;threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;group-policy Adisan-VPN internal&lt;/P&gt;&lt;P&gt;group-policy Adisan-VPN attributes&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec&lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value Adisan-VPN_splitTunnelAcl&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tunnel-group Adisan-VPN type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group Adisan-VPN general-attributes&lt;/P&gt;&lt;P&gt; address-pool VPN_POOL&lt;/P&gt;&lt;P&gt; default-group-policy Adisan-VPN&lt;/P&gt;&lt;P&gt;tunnel-group Adisan-VPN ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map THROTTLE_GRAITEC_FTP&lt;/P&gt;&lt;P&gt; match access-list THROTTLE_GRAITEC_FTP&lt;/P&gt;&lt;P&gt;class-map THROTTLE_FASTTRACK&lt;/P&gt;&lt;P&gt; match access-list outside_mpc&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map THROTTLE_GRAITEC_FTP&lt;/P&gt;&lt;P&gt; class THROTTLE_GRAITEC_FTP&lt;/P&gt;&lt;P&gt;&amp;nbsp; police output 10000000 20000&lt;/P&gt;&lt;P&gt;&amp;nbsp; police input 10000000 20000&lt;/P&gt;&lt;P&gt; class THROTTLE_FASTTRACK&lt;/P&gt;&lt;P&gt;&amp;nbsp; police input 6000000 12000&lt;/P&gt;&lt;P&gt;&amp;nbsp; police output 6000000 12000&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;service-policy THROTTLE_GRAITEC_FTP interface outside&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;Cryptochecksum:347696f9e2888a7c7c1adf4a1a20eeef&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 22:47:25 GMT</pubDate>
    <dc:creator>cristi_sys</dc:creator>
    <dc:date>2019-03-11T22:47:25Z</dc:date>
    <item>
      <title>Problem sending mails thought ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/problem-sending-mails-thought-asa-5505/m-p/1911812#M457698</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 subnets bought from my provider 194.102.98.128/27 and 194.102.98.160/27. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From my provider a have the following setup:&lt;/P&gt;&lt;PRE&gt;IP Address:&amp;nbsp; 86.120.151.66
Netmask:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.128
Gateway:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 86.120.151.1
DNS (1): 213.154.124.1
DNS (2): 193.231.252.1&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My IPs are static routed by my provider thought 86.120.151.66 . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the firewall I have the following set-up: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Outside Interface: 86.120.151.66/25 security level 0&lt;/P&gt;&lt;P&gt;DMZ interface: 194.102.98.129/27 security level 50&lt;/P&gt;&lt;P&gt;Inside Interface: 194.102.98.161/27 security level 100&lt;/P&gt;&lt;P&gt;0.0.0.0 0.0.0.0 [1/0] via 86.120.151.1, outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everything works perfectly except when I try to sent an email. The email gets sent (eventually), but afert a long waiting time, 45-60 sec. The connection is opened instally to the server but then just hangs there for 40-50 sec. The problem is that a have an aplication on a server that has to send confirmation emails, and that aplication is limited to a 30 sec timeout for conecting to the mail server, much less then the 45-60 sec that I have now. The mail server is hosted by a data center, it is not in my networks (location).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried deleting the ESMTP inspection, that doesn't work. Pinging my mail server rezults in a average time of 20 ms. And when a do a tracert the hight value in a&amp;nbsp; hop doesn't usually pass 80 ms, the average is 20-25 ms. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is ONLY when sending emails. Everything else works perfect, including receiving emails from the same server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My running config is: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname ASA-Adisys&lt;/P&gt;&lt;P&gt;domain-name Intern.ro&lt;/P&gt;&lt;P&gt;enable password 0./39zRW9yhKK/bO encrypted&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 91.220.232.66 &lt;A href="https://community.cisco.com/www.itarena.ro" target="_blank"&gt;www.itarena.ro&lt;/A&gt; description Adresa IP a site-ului&lt;/P&gt;&lt;P&gt;name 194.102.98.161 Inside_Gateway&lt;/P&gt;&lt;P&gt;name 172.16.10.96 VPN_Adress_POOL&lt;/P&gt;&lt;P&gt;name 194.102.98.185 Adisys_Cara&lt;/P&gt;&lt;P&gt;name 194.102.98.165 Adisys_Cyclope&lt;/P&gt;&lt;P&gt;name 194.102.98.184 Adisys_UC540W description Adresa de WAN Adisys&lt;/P&gt;&lt;P&gt;name 194.102.98.133 DMZ_Agnor_IP1&lt;/P&gt;&lt;P&gt;name 194.102.98.134 DMZ_Agnor_IP2&lt;/P&gt;&lt;P&gt;name 194.102.98.146 DMZ_Fasttrack&lt;/P&gt;&lt;P&gt;name 194.102.98.150 DMZ_Graitec_Auth_Server&lt;/P&gt;&lt;P&gt;name 194.102.98.148 DMZ_Graitec_Axapta&lt;/P&gt;&lt;P&gt;name 194.102.98.149 DMZ_Graitec_Citrix&lt;/P&gt;&lt;P&gt;name 194.102.98.147 DMZ_Graitec_FTP&lt;/P&gt;&lt;P&gt;name 194.102.98.144 DMZ_Jeka&lt;/P&gt;&lt;P&gt;name 194.102.98.142 DMZ_Agras&lt;/P&gt;&lt;P&gt;name 194.102.98.132 DMZ_Router_Dlink description Adresa de la router-ul din spate&lt;/P&gt;&lt;P&gt;name 89.122.106.51 Graitec_Remote_PC1 description Calculator dupa care se face RDC Graitec&lt;/P&gt;&lt;P&gt;name 89.122.49.40 Graitec_Remote_PC3 description Calculator dupa care se face RDC Graitec&lt;/P&gt;&lt;P&gt;name 184.154.10.114 Graitec_mail.graitec.info&lt;/P&gt;&lt;P&gt;name 89.120.49.209 Graitec_mail.graitec.net description Calculator dupa care se face RDC Graitec&lt;/P&gt;&lt;P&gt;name 89.122.248.141 Graitec_mail.graitec.ro description Calculator dupa care se face RDC Graitec&lt;/P&gt;&lt;P&gt;name 81.80.156.221 Graitec_mailhost.graitec.com&lt;/P&gt;&lt;P&gt;name 82.137.9.82 Test_IP description IP de test&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address Inside_Gateway 255.255.255.224&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; description IP Internet&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 86.120.151.66 255.255.255.128&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan12&lt;/P&gt;&lt;P&gt; description Retea clienti&lt;/P&gt;&lt;P&gt; no forward interface Vlan1&lt;/P&gt;&lt;P&gt; nameif DMZ&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt; ip address 194.102.98.129 255.255.255.224&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt; switchport access vlan 12&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt; switchport access vlan 12&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone EEST 2&lt;/P&gt;&lt;P&gt;clock summer-time EEDT recurring last Sun Mar 3:00 last Sun Oct 4:00&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; domain-name Intern.ro&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_1&lt;/P&gt;&lt;P&gt; network-object host Graitec_mail.graitec.net&lt;/P&gt;&lt;P&gt; network-object host Graitec_Remote_PC1&lt;/P&gt;&lt;P&gt; network-object host Graitec_mail.graitec.ro&lt;/P&gt;&lt;P&gt; network-object host Graitec_Remote_PC3&lt;/P&gt;&lt;P&gt; network-object host Test_IP&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_2&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Axapta&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Citrix&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Auth_Server&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_3&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Axapta&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Citrix&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Auth_Server&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_4&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Citrix&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Auth_Server&lt;/P&gt;&lt;P&gt; network-object host Inside_Gateway&lt;/P&gt;&lt;P&gt; network-object host Adisys_UC540W&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_5&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Axapta&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Citrix&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Auth_Server&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_6&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Citrix&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Auth_Server&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_7&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Axapta&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Citrix&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Auth_Server&lt;/P&gt;&lt;P&gt;object-group protocol TCPUDP&lt;/P&gt;&lt;P&gt; protocol-object udp&lt;/P&gt;&lt;P&gt; protocol-object tcp&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_8&lt;/P&gt;&lt;P&gt; network-object host Inside_Gateway&lt;/P&gt;&lt;P&gt; network-object host Adisys_UC540W&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_10&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_FTP&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Axapta&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Citrix&lt;/P&gt;&lt;P&gt; network-object host DMZ_Graitec_Auth_Server&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_9&lt;/P&gt;&lt;P&gt; network-object host Graitec_mail.graitec.info&lt;/P&gt;&lt;P&gt; network-object host Graitec_mailhost.graitec.com&lt;/P&gt;&lt;P&gt; network-object host Graitec_mail.graitec.net&lt;/P&gt;&lt;P&gt; network-object host Graitec_mail.graitec.ro&lt;/P&gt;&lt;P&gt; network-object host Graitec_Remote_PC3&lt;/P&gt;&lt;P&gt;object-group protocol DM_INLINE_PROTOCOL_1&lt;/P&gt;&lt;P&gt; protocol-object icmp&lt;/P&gt;&lt;P&gt; protocol-object icmp6&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_1 tcp&lt;/P&gt;&lt;P&gt; port-object eq 2525&lt;/P&gt;&lt;P&gt; port-object eq 465&lt;/P&gt;&lt;P&gt; port-object eq pop3&lt;/P&gt;&lt;P&gt; port-object eq smtp&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow access to Auth, Axapta, Citrix to 3389&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp object-group DM_INLINE_NETWORK_1 object-group DM_INLINE_NETWORK_2 eq 3389&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow access to Citrix, Auth, Adisys_WAN to port 443&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object-group DM_INLINE_NETWORK_4 eq https&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow access to Auth, Axapta, Citrix from port 80&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any eq www object-group DM_INLINE_NETWORK_3&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow access to Auth, Axapta, Citrix from port 53&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object-group TCPUDP any eq domain object-group DM_INLINE_NETWORK_5&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow access to Auth, Citrix from port 443&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any eq https object-group DM_INLINE_NETWORK_6&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp object-group DM_INLINE_NETWORK_9 object-group DM_INLINE_NETWORK_10 object-group DM_INLINE_TCP_1&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow Ping to graitec servers&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object-group DM_INLINE_PROTOCOL_1 any any&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Deny any to Axapta, Auth, Citrix&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended deny ip any object-group DM_INLINE_NETWORK_7&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow access to Adisys_WAN from Non500-isakmp&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit udp any host Adisys_UC540W eq 4500&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow access to Adisys_WAN from Isakmp&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit udp any object-group DM_INLINE_NETWORK_8 eq isakmp&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow access to Adisys_WAN from esp&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit esp any host Adisys_UC540W&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow access to Adisys_WAN from AHP&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ah any host Adisys_UC540W&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow syslog messeger from ITarena.ro to Cyclope Syslog&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit udp host &lt;A href="https://community.cisco.com/www.itarena.ro" target="_blank"&gt;www.itarena.ro&lt;/A&gt; host Adisys_Cyclope eq syslog&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow 113 from &lt;A href="http://www.itarena.ro" target="_blank"&gt;www.itarena.ro&lt;/A&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp host &lt;A href="https://community.cisco.com/www.itarena.ro" target="_blank"&gt;www.itarena.ro&lt;/A&gt; 194.102.98.160 255.255.255.224 eq ident&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow Mark Vision from internet&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host Adisys_UC540W eq 9788&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host DMZ_Router_Dlink eq www&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow TFTP for Voice&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip VPN_Adress_POOL 255.255.255.240 194.102.98.160 255.255.255.224 inactive&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow TFTP from inside to VPN&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip 194.102.98.160 255.255.255.224 VPN_Adress_POOL 255.255.255.240 inactive&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Deny any to Inside Network 194.102.98.160/27&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended deny ip any 194.102.98.160 255.255.255.224&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip any 194.102.98.128 255.255.255.224&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow Ping&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list THROTTLE_GRAITEC_FTP extended permit ip host DMZ_Graitec_FTP any&lt;/P&gt;&lt;P&gt;access-list THROTTLE_GRAITEC_FTP extended permit ip any host DMZ_Graitec_FTP&lt;/P&gt;&lt;P&gt;access-list Adisan-VPN_splitTunnelAcl standard permit 194.102.98.160 255.255.255.224&lt;/P&gt;&lt;P&gt;access-list outside_mpc extended permit ip host DMZ_Fasttrack any&lt;/P&gt;&lt;P&gt;access-list outside_mpc extended permit ip any host DMZ_Fasttrack&lt;/P&gt;&lt;P&gt;access-list outside_access_in_1 remark Allow&lt;/P&gt;&lt;P&gt;access-list outside_access_in_1 extended permit tcp any any eq https&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging trap warnings&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging host inside Adisys_UC540W&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;ip local pool VPN_POOL 172.16.10.97-172.16.10.110&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;access-group outside_access_in_1 in interface outside control-plane&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 86.120.151.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 194.102.98.160 255.255.255.224 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime seconds 28800&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;/P&gt;&lt;P&gt;crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside&lt;/P&gt;&lt;P&gt;crypto isakmp enable outside&lt;/P&gt;&lt;P&gt;crypto isakmp policy 5&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; encryption 3des&lt;/P&gt;&lt;P&gt; hash sha&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 86400&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; encryption des&lt;/P&gt;&lt;P&gt; hash sha&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 86400&lt;/P&gt;&lt;P&gt;crypto isakmp policy 30&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; encryption aes&lt;/P&gt;&lt;P&gt; hash sha&lt;/P&gt;&lt;P&gt; group 5&lt;/P&gt;&lt;P&gt; lifetime 86400&lt;/P&gt;&lt;P&gt;no vpn-addr-assign aaa&lt;/P&gt;&lt;P&gt;no vpn-addr-assign dhcp&lt;/P&gt;&lt;P&gt;telnet 194.102.98.160 255.255.255.224 inside&lt;/P&gt;&lt;P&gt;telnet timeout 15&lt;/P&gt;&lt;P&gt;ssh 194.102.98.160 255.255.255.224 inside&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address Adisys_Cyclope-194.102.98.170 inside&lt;/P&gt;&lt;P&gt;dhcpd dns 8.8.8.8 8.8.4.4 interface inside&lt;/P&gt;&lt;P&gt;dhcpd enable inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics&lt;/P&gt;&lt;P&gt;threat-detection statistics host number-of-rate 2&lt;/P&gt;&lt;P&gt;threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;group-policy Adisan-VPN internal&lt;/P&gt;&lt;P&gt;group-policy Adisan-VPN attributes&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec&lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value Adisan-VPN_splitTunnelAcl&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tunnel-group Adisan-VPN type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group Adisan-VPN general-attributes&lt;/P&gt;&lt;P&gt; address-pool VPN_POOL&lt;/P&gt;&lt;P&gt; default-group-policy Adisan-VPN&lt;/P&gt;&lt;P&gt;tunnel-group Adisan-VPN ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map THROTTLE_GRAITEC_FTP&lt;/P&gt;&lt;P&gt; match access-list THROTTLE_GRAITEC_FTP&lt;/P&gt;&lt;P&gt;class-map THROTTLE_FASTTRACK&lt;/P&gt;&lt;P&gt; match access-list outside_mpc&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map THROTTLE_GRAITEC_FTP&lt;/P&gt;&lt;P&gt; class THROTTLE_GRAITEC_FTP&lt;/P&gt;&lt;P&gt;&amp;nbsp; police output 10000000 20000&lt;/P&gt;&lt;P&gt;&amp;nbsp; police input 10000000 20000&lt;/P&gt;&lt;P&gt; class THROTTLE_FASTTRACK&lt;/P&gt;&lt;P&gt;&amp;nbsp; police input 6000000 12000&lt;/P&gt;&lt;P&gt;&amp;nbsp; police output 6000000 12000&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;service-policy THROTTLE_GRAITEC_FTP interface outside&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;Cryptochecksum:347696f9e2888a7c7c1adf4a1a20eeef&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:47:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-sending-mails-thought-asa-5505/m-p/1911812#M457698</guid>
      <dc:creator>cristi_sys</dc:creator>
      <dc:date>2019-03-11T22:47:25Z</dc:date>
    </item>
    <item>
      <title>Problem sending mails thought ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/problem-sending-mails-thought-asa-5505/m-p/1911813#M457700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Did you ever find a solution to why the ASA is doing this? Im having the same problem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Aug 2012 21:17:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-sending-mails-thought-asa-5505/m-p/1911813#M457700</guid>
      <dc:creator>plimpias</dc:creator>
      <dc:date>2012-08-31T21:17:33Z</dc:date>
    </item>
    <item>
      <title>Problem sending mails thought ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/problem-sending-mails-thought-asa-5505/m-p/1911814#M457702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please explain your issue and the desing of your network so we can help you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Aug 2012 22:55:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-sending-mails-thought-asa-5505/m-p/1911814#M457702</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-08-31T22:55:51Z</dc:date>
    </item>
    <item>
      <title>Problem sending mails thought ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/problem-sending-mails-thought-asa-5505/m-p/1911815#M457703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Please see the following post that i started.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://social.technet.microsoft.com/Forums/en-US/exchangesvrclients/thread/56717f7b-9638-4e0d-b22c-f1031c1d021c"&gt;http://social.technet.microsoft.com/Forums/en-US/exchangesvrclients/thread/56717f7b-9638-4e0d-b22c-f1031c1d021c&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have verified that this is indeed a problem when I have the ASA in place. Bypassing the ASA resolves the issue. I have no inspection in place. No time outs in place either. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having the same issue as the original person that started this post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When routing between two different segments with an exchange server and outlook clients on different networks, going through the ASA at random times the clients are experiencing hangs when sending emails in outlook. Aparently the other person fixed it by disabled RPC inspection on the juniper he has..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Aug 2012 23:30:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-sending-mails-thought-asa-5505/m-p/1911815#M457703</guid>
      <dc:creator>plimpias</dc:creator>
      <dc:date>2012-08-31T23:30:11Z</dc:date>
    </item>
  </channel>
</rss>

