<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cant send email - PIX 506 version 6.3(5) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cant-send-email-pix-506-version-6-3-5/m-p/594101#M498413</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This access list permit traffic from outside to inside what is ACL apllied to inside interface???? Why did you turned-off fixup of smtp (no fixup protocol smtp 25 ) try to enable fixup again with command  fixup protocol smtp 25 &lt;/P&gt;&lt;P&gt;M.&lt;/P&gt;&lt;P&gt;Hope that helps rate if it does&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 14 Aug 2006 07:19:25 GMT</pubDate>
    <dc:creator>m.sir</dc:creator>
    <dc:date>2006-08-14T07:19:25Z</dc:date>
    <item>
      <title>Cant send email - PIX 506 version 6.3(5)</title>
      <link>https://community.cisco.com/t5/network-security/cant-send-email-pix-506-version-6-3-5/m-p/594100#M498412</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently we are using pix version 6.3(5) 506 model for our email server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Policy rule pretty simple, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group service Email-ports tcp &lt;/P&gt;&lt;P&gt;  port-object eq 995 &lt;/P&gt;&lt;P&gt;  port-object eq 456 &lt;/P&gt;&lt;P&gt;  port-object eq smtp &lt;/P&gt;&lt;P&gt;  port-object eq 8188&lt;/P&gt;&lt;P&gt;  port-object eq pop3&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any interface outside object-group Email-ports&lt;/P&gt;&lt;P&gt;no fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue currently we are facing is, we are able recieve emials but we cannot send emials.&lt;/P&gt;&lt;P&gt;any advice?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Zaki&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:06:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-send-email-pix-506-version-6-3-5/m-p/594100#M498412</guid>
      <dc:creator>mdazadzaki</dc:creator>
      <dc:date>2020-02-21T09:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cant send email - PIX 506 version 6.3(5)</title>
      <link>https://community.cisco.com/t5/network-security/cant-send-email-pix-506-version-6-3-5/m-p/594101#M498413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This access list permit traffic from outside to inside what is ACL apllied to inside interface???? Why did you turned-off fixup of smtp (no fixup protocol smtp 25 ) try to enable fixup again with command  fixup protocol smtp 25 &lt;/P&gt;&lt;P&gt;M.&lt;/P&gt;&lt;P&gt;Hope that helps rate if it does&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2006 07:19:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-send-email-pix-506-version-6-3-5/m-p/594101#M498413</guid>
      <dc:creator>m.sir</dc:creator>
      <dc:date>2006-08-14T07:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cant send email - PIX 506 version 6.3(5)</title>
      <link>https://community.cisco.com/t5/network-security/cant-send-email-pix-506-version-6-3-5/m-p/594102#M498415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes this access list permits traffic form the outside to the inside based on the ports that have been configured as below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 192.168.1.0 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface smtp LotusDomino smtp netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 8188 LotusDomino https netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 465 LotusDomino 465 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 995 LotusDomino 995 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the business requirement is to allow access from the outside network (any) to access the the inside emial server (lotusdomino) bases on the ports confgured above. As for the inside interface, allow any to any policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so far there is no problem accessing the services from outside network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i read some comments from this forums to disable the no fixup protocol smtp if there is email server sending/recieveing problems. please correct me if i got it all wrong. Many thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;kind regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Zaki&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2006 07:47:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-send-email-pix-506-version-6-3-5/m-p/594102#M498415</guid>
      <dc:creator>mdazadzaki</dc:creator>
      <dc:date>2006-08-14T07:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cant send email - PIX 506 version 6.3(5)</title>
      <link>https://community.cisco.com/t5/network-security/cant-send-email-pix-506-version-6-3-5/m-p/594103#M498417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check your DNS to make sure from the server your can resolve name.  NSLOOKUP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2006 10:56:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-send-email-pix-506-version-6-3-5/m-p/594103#M498417</guid>
      <dc:creator>starlingsolon</dc:creator>
      <dc:date>2006-08-14T10:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cant send email - PIX 506 version 6.3(5)</title>
      <link>https://community.cisco.com/t5/network-security/cant-send-email-pix-506-version-6-3-5/m-p/594104#M498419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;my collegue commented based on the config.. he mention that port smtp is not available simply because it has being used for the outbound traffic. that makes it unable to send emials. however please verify the following config and comment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface ethernet0 auto&lt;/P&gt;&lt;P&gt;interface ethernet1 auto&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;name 192.168.1.28 LotusSametime&lt;/P&gt;&lt;P&gt;name 192.168.1.27 LotusDomino&lt;/P&gt;&lt;P&gt;object-group service BIBDEmail-ports tcp &lt;/P&gt;&lt;P&gt;  port-object eq 995 &lt;/P&gt;&lt;P&gt;  port-object eq 456 &lt;/P&gt;&lt;P&gt;  port-object eq smtp &lt;/P&gt;&lt;P&gt;  port-object eq 8188 &lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any interface outside object-group BIBDEmail-ports &lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 192.168.1.0 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface smtp LotusDomino smtp netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 8188 LotusDomino https netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 465 LotusDomino 465 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 995 LotusDomino 995 netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your help is appreciated&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Aug 2006 01:06:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-send-email-pix-506-version-6-3-5/m-p/594104#M498419</guid>
      <dc:creator>mdazadzaki</dc:creator>
      <dc:date>2006-08-15T01:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cant send email - PIX 506 version 6.3(5)</title>
      <link>https://community.cisco.com/t5/network-security/cant-send-email-pix-506-version-6-3-5/m-p/594105#M498420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI  ..&lt;/P&gt;&lt;P&gt;Can you please check whether you have an access-list applied to the INSIDE interface ..  If you do make sure you are allowing outbound access as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hop eit helps  ..  please rate it if it does !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Aug 2006 01:22:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-send-email-pix-506-version-6-3-5/m-p/594105#M498420</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2006-08-15T01:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cant send email - PIX 506 version 6.3(5)</title>
      <link>https://community.cisco.com/t5/network-security/cant-send-email-pix-506-version-6-3-5/m-p/594106#M498421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Zaki,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please be informed that, disabling the protocol inspection on PIX for SMTP/ESMTP is NOT advisable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May I request you to allow the protocol inspection by command fixup protocol smtp 25.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Wilson Samuel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Aug 2006 14:42:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cant-send-email-pix-506-version-6-3-5/m-p/594106#M498421</guid>
      <dc:creator>Wilson Samuel</dc:creator>
      <dc:date>2006-08-15T14:42:18Z</dc:date>
    </item>
  </channel>
</rss>

