<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ZBF - SMTP issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/zbf-smtp-issue/m-p/1713901#M561577</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="long_text" id="result_box"&gt;&lt;SPAN style="background-color: #ffffff;" title="o ZBF está dropping pacotes, mesmo eles estando liberados"&gt;My ZBF is dropping some SMTP packets, and allowing others...even though they're &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="long_text short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;allowed. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My ZBF (SMTP) configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type inspect match-all c_servidoressmtp&lt;BR /&gt; description Class Map allowing SMTP Access&lt;BR /&gt; match access-group name ACL_SMTP&lt;BR /&gt; match protocol smtp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect p_EXTtoSRV&lt;BR /&gt;&lt;SPAN class="long_text short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; class type inspect c_servidoressmtp&lt;BR /&gt;&amp;nbsp; inspect&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip access-list extended ACL_SMTP&lt;BR /&gt; remark ACL SMTP SERVERS&lt;BR /&gt; permit ip any host 200.19.105.193&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Log's:&lt;/P&gt;&lt;P&gt;May 30 13:59:18 udesc-servidores/udesc-servidores 2809973: *May 30 13:59:32: %FW-6-LOG_SUMMARY: 63 tcp packets were dropped from 209.85.216.45:46013 =&amp;gt; 200.19.105.193:25 (target:class)-(zp_EXTtoSRV:c_servidoressmtp)&lt;BR /&gt;May 30 13:59:18 udesc-servidores/udesc-servidores 2809974: *May 30 13:59:32: %FW-6-LOG_SUMMARY: 63 tcp packets were dropped from 209.85.216.45:61800 =&amp;gt; 200.19.105.193:25 (target:class)-(zp_EXTtoSRV:c_servidoressmtp)&lt;BR /&gt;May 30 13:59:18 udesc-servidores/udesc-servidores 2809976: *May 30 13:59:32: %FW-6-LOG_SUMMARY: 46 tcp packets were dropped from 74.125.82.45:44331 =&amp;gt; 200.19.105.193:25 (target:class)-(zp_EXTtoSRV:c_servidoressmtp)&lt;BR /&gt;May 30 13:59:18 udesc-servidores/udesc-servidores 2809980: *May 30 13:59:32: %FW-6-LOG_SUMMARY: 4 tcp packets were dropped from 201.23.81.230:44768 =&amp;gt; 200.19.105.193:25 (target:class)-(zp_EXTtoSRV:c_servidoressmtp)&lt;BR /&gt;May 30 13:59:18 udesc-servidores/udesc-servidores 2809989: *May 30 13:59:32: %FW-6-LOG_SUMMARY: 1 tcp packet were dropped from 209.85.213.185:38750 =&amp;gt; 200.19.105.193:25 (target:class)-(zp_EXTtoSRV:c_servidoressmtp)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#&lt;SPAN class="long_text short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;sh policy-map type inspect zone-pair zp_EXTtoSRV&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Class-map: c_servidoressmtp (match-all)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Match: access-group name ACL_SMTP&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Match: protocol smtp&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&amp;nbsp;&amp;nbsp; Inspect&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Packet inspection statistics [process switch:fast switch]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp packets: [111655:55981644]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session creations since subsystem startup or last reset 1142351&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Current session counts (estab/half-open/terminating) [20:0:0]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Maxever session counts (estab/half-open/terminating) [181:52:50]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last session created 00:00:04&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last statistic reset never&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last session creation rate 28&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Maxever session creation rate 610&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last half-open session total 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP reassembly statistics&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; received 0 packets out-of-order; dropped 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; peak memory usage 0 KB; current usage: 0 KB&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; peak queue length 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone &lt;SPAN class="long_text short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;have any idea&lt;/SPAN&gt;&lt;SPAN title="Clique para mostrar traduções alternativas"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Fernando&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:40:07 GMT</pubDate>
    <dc:creator>fernandoseidler</dc:creator>
    <dc:date>2019-03-11T20:40:07Z</dc:date>
    <item>
      <title>ZBF - SMTP issue</title>
      <link>https://community.cisco.com/t5/network-security/zbf-smtp-issue/m-p/1713901#M561577</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="long_text" id="result_box"&gt;&lt;SPAN style="background-color: #ffffff;" title="o ZBF está dropping pacotes, mesmo eles estando liberados"&gt;My ZBF is dropping some SMTP packets, and allowing others...even though they're &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="long_text short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;allowed. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My ZBF (SMTP) configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type inspect match-all c_servidoressmtp&lt;BR /&gt; description Class Map allowing SMTP Access&lt;BR /&gt; match access-group name ACL_SMTP&lt;BR /&gt; match protocol smtp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect p_EXTtoSRV&lt;BR /&gt;&lt;SPAN class="long_text short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; class type inspect c_servidoressmtp&lt;BR /&gt;&amp;nbsp; inspect&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip access-list extended ACL_SMTP&lt;BR /&gt; remark ACL SMTP SERVERS&lt;BR /&gt; permit ip any host 200.19.105.193&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Log's:&lt;/P&gt;&lt;P&gt;May 30 13:59:18 udesc-servidores/udesc-servidores 2809973: *May 30 13:59:32: %FW-6-LOG_SUMMARY: 63 tcp packets were dropped from 209.85.216.45:46013 =&amp;gt; 200.19.105.193:25 (target:class)-(zp_EXTtoSRV:c_servidoressmtp)&lt;BR /&gt;May 30 13:59:18 udesc-servidores/udesc-servidores 2809974: *May 30 13:59:32: %FW-6-LOG_SUMMARY: 63 tcp packets were dropped from 209.85.216.45:61800 =&amp;gt; 200.19.105.193:25 (target:class)-(zp_EXTtoSRV:c_servidoressmtp)&lt;BR /&gt;May 30 13:59:18 udesc-servidores/udesc-servidores 2809976: *May 30 13:59:32: %FW-6-LOG_SUMMARY: 46 tcp packets were dropped from 74.125.82.45:44331 =&amp;gt; 200.19.105.193:25 (target:class)-(zp_EXTtoSRV:c_servidoressmtp)&lt;BR /&gt;May 30 13:59:18 udesc-servidores/udesc-servidores 2809980: *May 30 13:59:32: %FW-6-LOG_SUMMARY: 4 tcp packets were dropped from 201.23.81.230:44768 =&amp;gt; 200.19.105.193:25 (target:class)-(zp_EXTtoSRV:c_servidoressmtp)&lt;BR /&gt;May 30 13:59:18 udesc-servidores/udesc-servidores 2809989: *May 30 13:59:32: %FW-6-LOG_SUMMARY: 1 tcp packet were dropped from 209.85.213.185:38750 =&amp;gt; 200.19.105.193:25 (target:class)-(zp_EXTtoSRV:c_servidoressmtp)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#&lt;SPAN class="long_text short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;sh policy-map type inspect zone-pair zp_EXTtoSRV&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Class-map: c_servidoressmtp (match-all)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Match: access-group name ACL_SMTP&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Match: protocol smtp&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&amp;nbsp;&amp;nbsp; Inspect&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Packet inspection statistics [process switch:fast switch]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp packets: [111655:55981644]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session creations since subsystem startup or last reset 1142351&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Current session counts (estab/half-open/terminating) [20:0:0]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Maxever session counts (estab/half-open/terminating) [181:52:50]&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last session created 00:00:04&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last statistic reset never&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last session creation rate 28&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Maxever session creation rate 610&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last half-open session total 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP reassembly statistics&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; received 0 packets out-of-order; dropped 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; peak memory usage 0 KB; current usage: 0 KB&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; peak queue length 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone &lt;SPAN class="long_text short_text" id="result_box" lang="en"&gt;&lt;SPAN class="hps" title="Clique para mostrar traduções alternativas"&gt;have any idea&lt;/SPAN&gt;&lt;SPAN title="Clique para mostrar traduções alternativas"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Fernando&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:40:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbf-smtp-issue/m-p/1713901#M561577</guid>
      <dc:creator>fernandoseidler</dc:creator>
      <dc:date>2019-03-11T20:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: ZBF - SMTP issue</title>
      <link>https://community.cisco.com/t5/network-security/zbf-smtp-issue/m-p/1713902#M561578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The public smtp server might be using ESMTP rather than SMTP. If so, use "match protocol smtp extended" instead. If that's not it, you might want to open a TAC case to investigate further. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jun 2011 19:16:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/zbf-smtp-issue/m-p/1713902#M561578</guid>
      <dc:creator>Ronaldo Renato Punzalan</dc:creator>
      <dc:date>2011-06-14T19:16:41Z</dc:date>
    </item>
  </channel>
</rss>

