<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic smtp filtering problems in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/smtp-filtering-problems/m-p/1601040#M566677</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everytime I turn on esmtp filtering for a client using Exchange Server, things end up getting blocked and it never logs anything it blocks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's my map.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;policy-map type inspect esmtp secure_smtp_map&lt;BR /&gt; parameters&lt;BR /&gt;&amp;nbsp; no mask-banner&lt;BR /&gt;&amp;nbsp; special-character action drop-connection log&lt;BR /&gt;&amp;nbsp; allow-tls action log&lt;BR /&gt; match sender-address length gt 320 &lt;BR /&gt;&amp;nbsp; drop-connection log&lt;BR /&gt; match MIME filename length gt 255 &lt;BR /&gt;&amp;nbsp; drop-connection log&lt;BR /&gt; match cmd line length gt 512 &lt;BR /&gt;&amp;nbsp; drop-connection log&lt;BR /&gt; match cmd verb VRFY &lt;BR /&gt;&amp;nbsp; mask log&lt;BR /&gt; match cmd RCPT count gt 100 &lt;BR /&gt;&amp;nbsp; drop-connection log&lt;BR /&gt; match body line length gt 998 &lt;BR /&gt;&amp;nbsp; drop-connection log&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone want to guess what it is since there is no logging?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This time&amp;nbsp; the problem was hotmail users sending to internal Exchange users were getting bounced&amp;nbsp; with this message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;Reporting-MTA: dns;blu0-omc2-s22.blu0.hotmail.com&lt;BR /&gt;Received-From-MTA: dns;BLU156-W41&lt;BR /&gt;Arrival-Date: Fri, 11 Feb 2011 10:17:19 -0800&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Final-Recipient: rfc822;&lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:someone@somewhere.us" target="_blank"&gt;someone@somewhere.us&lt;/A&gt;&lt;BR /&gt;Action: failed&lt;BR /&gt;Status: 5.3.3&lt;BR /&gt;Diagnostic-Code: smtp;500 5.3.3 Unrecognized command&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the last time it was an out-of-office autorepsonder with the same map.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 19:49:44 GMT</pubDate>
    <dc:creator>lcaruso</dc:creator>
    <dc:date>2019-03-11T19:49:44Z</dc:date>
    <item>
      <title>smtp filtering problems</title>
      <link>https://community.cisco.com/t5/network-security/smtp-filtering-problems/m-p/1601040#M566677</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everytime I turn on esmtp filtering for a client using Exchange Server, things end up getting blocked and it never logs anything it blocks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's my map.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;policy-map type inspect esmtp secure_smtp_map&lt;BR /&gt; parameters&lt;BR /&gt;&amp;nbsp; no mask-banner&lt;BR /&gt;&amp;nbsp; special-character action drop-connection log&lt;BR /&gt;&amp;nbsp; allow-tls action log&lt;BR /&gt; match sender-address length gt 320 &lt;BR /&gt;&amp;nbsp; drop-connection log&lt;BR /&gt; match MIME filename length gt 255 &lt;BR /&gt;&amp;nbsp; drop-connection log&lt;BR /&gt; match cmd line length gt 512 &lt;BR /&gt;&amp;nbsp; drop-connection log&lt;BR /&gt; match cmd verb VRFY &lt;BR /&gt;&amp;nbsp; mask log&lt;BR /&gt; match cmd RCPT count gt 100 &lt;BR /&gt;&amp;nbsp; drop-connection log&lt;BR /&gt; match body line length gt 998 &lt;BR /&gt;&amp;nbsp; drop-connection log&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone want to guess what it is since there is no logging?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This time&amp;nbsp; the problem was hotmail users sending to internal Exchange users were getting bounced&amp;nbsp; with this message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;Reporting-MTA: dns;blu0-omc2-s22.blu0.hotmail.com&lt;BR /&gt;Received-From-MTA: dns;BLU156-W41&lt;BR /&gt;Arrival-Date: Fri, 11 Feb 2011 10:17:19 -0800&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Final-Recipient: rfc822;&lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:someone@somewhere.us" target="_blank"&gt;someone@somewhere.us&lt;/A&gt;&lt;BR /&gt;Action: failed&lt;BR /&gt;Status: 5.3.3&lt;BR /&gt;Diagnostic-Code: smtp;500 5.3.3 Unrecognized command&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the last time it was an out-of-office autorepsonder with the same map.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:49:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/smtp-filtering-problems/m-p/1601040#M566677</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2019-03-11T19:49:44Z</dc:date>
    </item>
    <item>
      <title>Re: smtp filtering problems</title>
      <link>https://community.cisco.com/t5/network-security/smtp-filtering-problems/m-p/1601041#M566678</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Caruso,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Would you please do a "show tech" and grab the part for the service policy? It should open the SMTP inspection and tell us what are the fileds that the inspection is dropping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Feb 2011 15:01:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/smtp-filtering-problems/m-p/1601041#M566678</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-02-12T15:01:32Z</dc:date>
    </item>
    <item>
      <title>Re: smtp filtering problems</title>
      <link>https://community.cisco.com/t5/network-security/smtp-filtering-problems/m-p/1601042#M566679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When TAC was on the call which lasted a few hours we never saw those counters from show service-policy increment as we sent mail from hotmail accounts, if that's what you mean. As soon as I turned off the policy, incoming hotmail was being received.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had a similar problem with a different ASA at a different site with the same map. I don't belive the counters are working correctly.We had to turn it off at both sites because it doesn't give reliable reporting when something gets blocked and fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And why it doesn't create a syslog entry, well it seems there are a number of things that don't create syslog entries on these ASAs. Probably one of the biggest problems with this platform.Do you suppose we will ever see the day when all drops are logged as syslog entries no matter if they dropped on the outside interface, policy drops, or acl drops?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Feb 2011 20:14:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/smtp-filtering-problems/m-p/1601042#M566679</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2011-02-12T20:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: smtp filtering problems</title>
      <link>https://community.cisco.com/t5/network-security/smtp-filtering-problems/m-p/1601043#M566680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would do a packet capture on boths sides of the ASA with SMTP filtering enabled and then disabled, sending to HOTMAIL (probably during low-traffic hours) and inspect the SMTP data payload to determine the difference. Capture the full packet and analyze the two. Maybe your params for the below are too agressive (well, they most certainly are, thats why you're getting dropped)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;match sender-address length gt 320 &lt;BR /&gt;&amp;nbsp; drop-connection log&lt;BR /&gt;match cmd line length gt 512 &lt;BR /&gt;&amp;nbsp; drop-connection log&lt;BR /&gt;match cmd RCPT count gt 100 &lt;BR /&gt;&amp;nbsp; drop-connection log&lt;BR /&gt;match body line length gt 998 &lt;BR /&gt;&amp;nbsp; drop-connection log&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Feb 2011 10:42:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/smtp-filtering-problems/m-p/1601043#M566680</guid>
      <dc:creator>aman.diwakar</dc:creator>
      <dc:date>2011-02-13T10:42:43Z</dc:date>
    </item>
    <item>
      <title>Re: smtp filtering problems</title>
      <link>https://community.cisco.com/t5/network-security/smtp-filtering-problems/m-p/1601044#M566683</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm still trying to figure out why the TAC engineer on the case decided it was too hard to capture that traffic. He kept telling me there would be too many packets. I'll try it myself and see what happens. Thanks for your suggestion.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Feb 2011 14:13:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/smtp-filtering-problems/m-p/1601044#M566683</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2011-02-13T14:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: smtp filtering problems</title>
      <link>https://community.cisco.com/t5/network-security/smtp-filtering-problems/m-p/1601045#M566684</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;well..maybe because there is a large list of mx records for hotmail:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But that shouldnt be a show stopper, here is a list of hotmail mx records, you can double check&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;65.54.188.72&lt;BR /&gt;65.55.92.152&lt;BR /&gt;65.55.37.88&lt;BR /&gt;65.55.37.120&lt;BR /&gt;65.55.37.72&lt;BR /&gt;65.55.37.104&lt;BR /&gt;65.55.92.136&lt;BR /&gt;65.55.92.168&lt;BR /&gt;65.55.92.184&lt;BR /&gt;65.54.188.94&lt;BR /&gt;65.54.188.110&lt;BR /&gt;65.54.188.126&lt;BR /&gt;65.54.188.126&lt;BR /&gt;65.55.92.168&lt;BR /&gt;65.55.37.72&lt;BR /&gt;65.55.37.104&lt;BR /&gt;65.55.37.120&lt;BR /&gt;65.55.92.152&lt;BR /&gt;65.55.37.88&lt;BR /&gt;65.55.92.136&lt;BR /&gt;65.55.92.184&lt;BR /&gt;65.54.188.72&lt;BR /&gt;65.54.188.94&lt;BR /&gt;65.54.188.110&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just put them as source and destination address like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list capture permit tcp host 65.54.188.110 eq 25 host &lt;YOURMAILSERVER&gt;&lt;/YOURMAILSERVER&gt;&lt;/P&gt;&lt;P&gt;access-list capture permit tcp host &lt;YOURMAILSERVER&gt; host 65.54.188.110 eq 25&lt;/YOURMAILSERVER&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;capture in access-list capture interface inside&lt;/P&gt;&lt;P&gt;capture out access-list capture interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but..you have to make sure the size option and any other option in the capture command is configured (i havent looked at the capture command syntax in a while)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Feb 2011 07:40:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/smtp-filtering-problems/m-p/1601045#M566684</guid>
      <dc:creator>aman.diwakar</dc:creator>
      <dc:date>2011-02-15T07:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: smtp filtering problems</title>
      <link>https://community.cisco.com/t5/network-security/smtp-filtering-problems/m-p/1601046#M566685</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ahh...so many mx records...that was his reason.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll try your suggestions when I find time. Right now we just had to turn it off so mail would flow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You made some good suggestions. Appreciate it. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Feb 2011 03:50:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/smtp-filtering-problems/m-p/1601046#M566685</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2011-02-16T03:50:58Z</dc:date>
    </item>
  </channel>
</rss>

