<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enable SMTP on firewall cisco 1800 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/enable-smtp-on-firewall-cisco-1800/m-p/1599416#M587103</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;EM&gt;zone-pair security sdm-zp-in-out source in-zone destination out-zone&lt;/EM&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;EM&gt; service-policy type inspect sdm-inspect&lt;/EM&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV&gt;you are applying this policy from in to out and you are inspecting smtp so only return traffic from out to in is allowed.&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV&gt;If you want access from outside then you must apply separate policy for your smtp from out to in.&lt;/DIV&gt;&lt;DIV&gt;and get rid of match smtp in your class voice as it will be in a new class now.&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV&gt;Regards.&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV&gt;Alain.&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 21 Dec 2010 08:50:27 GMT</pubDate>
    <dc:creator>cadet alain</dc:creator>
    <dc:date>2010-12-21T08:50:27Z</dc:date>
    <item>
      <title>Enable SMTP on firewall cisco 1800</title>
      <link>https://community.cisco.com/t5/network-security/enable-smtp-on-firewall-cisco-1800/m-p/1599414#M587100</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a printer in my local network and it has a external smtp server for scanner propose.&lt;/P&gt;&lt;P&gt;Yesterday i enable the firewall with the SDM cause i wanted to block URLs. But now im not able to connect to port 25 to the smtp. I tried to clear some config but im not finding where the firewall is blocking the port 25.&lt;/P&gt;&lt;P&gt;Can someone help me&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service tcp-keepalives-in&lt;/P&gt;&lt;P&gt;service tcp-keepalives-out&lt;/P&gt;&lt;P&gt;service timestamps debug datetime msec localtime show-timezone&lt;/P&gt;&lt;P&gt;service timestamps log datetime msec localtime show-timezone&lt;/P&gt;&lt;P&gt;service password-encryption&lt;/P&gt;&lt;P&gt;service sequence-numbers&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname xxxx&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot-start-marker&lt;/P&gt;&lt;P&gt;boot-end-marker&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;security authentication failure rate 3 log&lt;/P&gt;&lt;P&gt;security passwords min-length 6&lt;/P&gt;&lt;P&gt;logging buffered 100200&lt;/P&gt;&lt;P&gt;logging console critical&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;aaa authentication login default local&lt;/DIV&gt;&lt;DIV&gt;aaa authorization exec default local&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;aaa session-id common&lt;/DIV&gt;&lt;DIV&gt;clock timezone PCTime -3&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;crypto pki trustpoint TP-self-signed-910902666&lt;/DIV&gt;&lt;DIV&gt; enrollment selfsigned&lt;/DIV&gt;&lt;DIV&gt; subject-name cn=IOS-Self-Signed-Certificate-910902666&lt;/DIV&gt;&lt;DIV&gt; revocation-check none&lt;/DIV&gt;&lt;DIV&gt; rsakeypair TP-self-signed-910902666&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;no ip cef&lt;/DIV&gt;&lt;DIV&gt;no ip dhcp use vrf connected&lt;/DIV&gt;&lt;DIV&gt;ip dhcp excluded-address 192.xxx.xxx.1&lt;/DIV&gt;&lt;DIV&gt;ip dhcp excluded-address 192.xxx.xxx.2&lt;/DIV&gt;&lt;DIV&gt;ip dhcp excluded-address 192.xxx.xxx.3&lt;/DIV&gt;&lt;DIV&gt;ip dhcp excluded-address 192.xxx.xxx.4&lt;/DIV&gt;&lt;DIV&gt;ip dhcp excluded-address 192.xxx.xxx.5&lt;/DIV&gt;&lt;DIV&gt;ip dhcp excluded-address 192.xxx.xxx.6&lt;/DIV&gt;&lt;DIV&gt;ip dhcp excluded-address 192.xxx.xxx.7&lt;/DIV&gt;&lt;DIV&gt;ip dhcp excluded-address 192.xxx.xxx.8&lt;/DIV&gt;&lt;DIV&gt;ip dhcp excluded-address 192.xxx.xxx.9&lt;/DIV&gt;&lt;DIV&gt;ip dhcp excluded-address 192.xxx.xxx.10&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;ip dhcp pool inetjj&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&amp;nbsp; network 192.xxx.xxx.0 255.255.255.0&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&amp;nbsp; dns-server xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&amp;nbsp; default-router 192.xxx.xxx.1&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&amp;nbsp; lease 2&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;ip domain name yourdomain.com&lt;/DIV&gt;&lt;DIV&gt;ip name-server 200.xxx.xxx.xxx&lt;/DIV&gt;&lt;DIV&gt;ip name-server 200.xxx.xxx.xxx&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;multilink bundle-name authenticated&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;parameter-map type urlfilter bloqueourl&lt;/DIV&gt;&lt;DIV&gt; alert off&lt;/DIV&gt;&lt;DIV&gt; source-interface FastEthernet0&lt;/DIV&gt;&lt;DIV&gt; allow-mode on&lt;/DIV&gt;&lt;DIV&gt; exclusive-domain deny &lt;A href="http://www.youtube.com" target="_blank"&gt;www.youtube.com&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt; exclusive-domain deny &lt;A href="http://www.facebook.com" target="_blank"&gt;www.facebook.com&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt; exclusive-domain deny &lt;A href="http://www.twitter.com" target="_blank"&gt;www.twitter.com&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt; exclusive-domain deny .taringa.net&lt;/DIV&gt;&lt;DIV&gt; exclusive-domain deny .rapidshare.com&lt;/DIV&gt;&lt;DIV&gt; exclusive-domain deny .megaupload.com&lt;/DIV&gt;&lt;DIV&gt; exclusive-domain deny .rojadirecta.com&lt;/DIV&gt;&lt;DIV&gt; exclusive-domain deny .justin.tv&lt;/DIV&gt;&lt;DIV&gt; exclusive-domain deny .rojadirecta.org&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;archive&lt;/DIV&gt;&lt;DIV&gt; log config&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; hidekeys&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;ip tcp synwait-time 10&lt;/DIV&gt;&lt;DIV&gt;ip ssh time-out 60&lt;/DIV&gt;&lt;DIV&gt;ip ssh authentication-retries 2&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;class-map type inspect match-any sdm-cls-insp-traffic&lt;/DIV&gt;&lt;DIV&gt; match protocol cuseeme&lt;/DIV&gt;&lt;DIV&gt; match protocol dns&lt;/DIV&gt;&lt;DIV&gt; match protocol ftp&lt;/DIV&gt;&lt;DIV&gt; match protocol h323&lt;/DIV&gt;&lt;DIV&gt; match protocol https&lt;/DIV&gt;&lt;DIV&gt; match protocol icmp&lt;/DIV&gt;&lt;DIV&gt; match protocol netshow&lt;/DIV&gt;&lt;DIV&gt; match protocol shell&lt;/DIV&gt;&lt;DIV&gt; match protocol realmedia&lt;/DIV&gt;&lt;DIV&gt; match protocol rtsp&lt;/DIV&gt;&lt;DIV&gt; match protocol sql-net&lt;/DIV&gt;&lt;DIV&gt; match protocol streamworks&lt;/DIV&gt;&lt;DIV&gt; match protocol tftp&lt;/DIV&gt;&lt;DIV&gt; match protocol vdolive&lt;/DIV&gt;&lt;DIV&gt; match protocol tcp&lt;/DIV&gt;&lt;DIV&gt; match protocol udp&lt;/DIV&gt;&lt;DIV&gt;class-map type inspect match-all sdm-insp-traffic&lt;/DIV&gt;&lt;DIV&gt; match class-map sdm-cls-insp-traffic&lt;/DIV&gt;&lt;DIV&gt;class-map type inspect match-any SDM-Voice-permit&lt;/DIV&gt;&lt;DIV&gt; match protocol h323&lt;/DIV&gt;&lt;DIV&gt; match protocol skinny&lt;/DIV&gt;&lt;DIV&gt; match protocol sip&lt;/DIV&gt;&lt;DIV&gt; match protocol smtp&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt; match protocol pop3&lt;/DIV&gt;&lt;DIV&gt;class-map type inspect match-any sdm-cls-icmp-access&lt;/DIV&gt;&lt;DIV&gt; match protocol icmp&lt;/DIV&gt;&lt;DIV&gt; match protocol tcp&lt;/DIV&gt;&lt;DIV&gt; match protocol udp&lt;/DIV&gt;&lt;DIV&gt;class-map type inspect match-all sdm-invalid-src&lt;/DIV&gt;&lt;DIV&gt; match access-group 106&lt;/DIV&gt;&lt;DIV&gt;class-map type inspect match-all sdm-icmp-access&lt;/DIV&gt;&lt;DIV&gt; match class-map sdm-cls-icmp-access&lt;/DIV&gt;&lt;DIV&gt;class-map type inspect match-all sdm-protocol-http&lt;/DIV&gt;&lt;DIV&gt; match protocol http&lt;/DIV&gt;&lt;DIV&gt; match access-group name Bloqueos&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;policy-map type inspect sdm-permit-icmpreply&lt;/DIV&gt;&lt;DIV&gt; class type inspect sdm-icmp-access&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect&lt;/DIV&gt;&lt;DIV&gt; class class-default&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; pass&lt;/DIV&gt;&lt;DIV&gt;policy-map type inspect sdm-inspect&lt;/DIV&gt;&lt;DIV&gt; class type inspect sdm-protocol-http&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; urlfilter bloqueourl&lt;/DIV&gt;&lt;DIV&gt; class type inspect sdm-invalid-src&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect&lt;/DIV&gt;&lt;DIV&gt; class type inspect sdm-insp-traffic&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect&lt;/DIV&gt;&lt;DIV&gt; class type inspect SDM-Voice-permit&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect&lt;/DIV&gt;&lt;DIV&gt; class class-default&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; pass&lt;/DIV&gt;&lt;DIV&gt;policy-map type inspect sdm-permit&lt;/DIV&gt;&lt;DIV&gt; class class-default&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; drop&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;zone security out-zone&lt;/DIV&gt;&lt;DIV&gt;zone security in-zone&lt;/DIV&gt;&lt;DIV&gt;zone-pair security sdm-zp-self-out source self destination out-zone&lt;/DIV&gt;&lt;DIV&gt; service-policy type inspect sdm-permit-icmpreply&lt;/DIV&gt;&lt;DIV&gt;zone-pair security sdm-zp-out-self source out-zone destination self&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt; service-policy type inspect sdm-permit&lt;/DIV&gt;&lt;DIV&gt;zone-pair security sdm-zp-in-out source in-zone destination out-zone&lt;/DIV&gt;&lt;DIV&gt; service-policy type inspect sdm-inspect&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface FastEthernet0&lt;/DIV&gt;&lt;DIV&gt; description $ES_WAN$$ETH-WAN$$FW_OUTSIDE$&lt;/DIV&gt;&lt;DIV&gt; ip address xxx.xxx.xxx.xxx 255.255.255.248&lt;/DIV&gt;&lt;DIV&gt; ip nat outside&lt;/DIV&gt;&lt;DIV&gt; no ip virtual-reassembly&lt;/DIV&gt;&lt;DIV&gt; zone-member security out-zone&lt;/DIV&gt;&lt;DIV&gt; ip route-cache flow&lt;/DIV&gt;&lt;DIV&gt; duplex auto&lt;/DIV&gt;&lt;DIV&gt; speed auto&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface BRI0&lt;/DIV&gt;&lt;DIV&gt; no ip address&lt;/DIV&gt;&lt;DIV&gt; encapsulation hdlc&lt;/DIV&gt;&lt;DIV&gt; ip route-cache flow&lt;/DIV&gt;&lt;DIV&gt; shutdown&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface FastEthernet1&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface FastEthernet2&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface FastEthernet3&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface FastEthernet4&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface FastEthernet5&lt;/DIV&gt;&lt;DIV&gt; switchport access vlan 100&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface FastEthernet6&lt;/DIV&gt;&lt;DIV&gt; switchport access vlan 100&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface FastEthernet7&lt;/DIV&gt;&lt;DIV&gt; switchport access vlan 100&lt;/DIV&gt;&lt;DIV&gt; switchport mode trunk&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;interface FastEthernet8&lt;/DIV&gt;&lt;DIV&gt; switchport access vlan 100&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface ATM0&lt;/DIV&gt;&lt;DIV&gt; no ip address&lt;/DIV&gt;&lt;DIV&gt; shutdown&lt;/DIV&gt;&lt;DIV&gt; no atm ilmi-keepalive&lt;/DIV&gt;&lt;DIV&gt; dsl operating-mode auto&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface Vlan1&lt;/DIV&gt;&lt;DIV&gt; description $FW_INSIDE$&lt;/DIV&gt;&lt;DIV&gt; ip address 1xxx.xxx.xxx.xxx 255.255.254.0&lt;/DIV&gt;&lt;DIV&gt; ip nat inside&lt;/DIV&gt;&lt;DIV&gt; ip virtual-reassembly&lt;/DIV&gt;&lt;DIV&gt; zone-member security in-zone&lt;/DIV&gt;&lt;DIV&gt; ip route-cache flow&lt;/DIV&gt;&lt;DIV&gt; ip tcp adjust-mss 1452&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface Vlan100&lt;/DIV&gt;&lt;DIV&gt; description JJINET$FW_INSIDE$&lt;/DIV&gt;&lt;DIV&gt; ip address 1xxx.xxx.xxx.xxx 255.255.255.0&lt;/DIV&gt;&lt;DIV&gt; ip nat inside&lt;/DIV&gt;&lt;DIV&gt; ip virtual-reassembly&lt;/DIV&gt;&lt;DIV&gt; zone-member security in-zone&lt;/DIV&gt;&lt;DIV&gt; ip route-cache flow&lt;/DIV&gt;&lt;DIV&gt; ip tcp adjust-mss 1452&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;ip forward-protocol nd&lt;/DIV&gt;&lt;DIV&gt;ip route 0.0.0.0 0.0.0.0 1xxx.xxx.xxx.xxx&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;ip http server&lt;/DIV&gt;&lt;DIV&gt;ip http access-class 23&lt;/DIV&gt;&lt;DIV&gt;ip http authentication local&lt;/DIV&gt;&lt;DIV&gt;ip http secure-server&lt;/DIV&gt;&lt;DIV&gt;ip http timeout-policy idle 60 life 86400 requests 10000&lt;/DIV&gt;&lt;DIV&gt;ip nat pool rdesktop 172.xxx.xxx.57 172.xxx.xxx.57 netmask 255.255.255.0 type rotary&lt;/DIV&gt;&lt;DIV&gt;ip nat inside source route-map SDM_RMAP_1 interface FastEthernet0 overload&lt;/DIV&gt;&lt;DIV&gt;ip nat inside destination list 100 pool rdesktop&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;ip access-list extended Bloqueos&lt;/DIV&gt;&lt;DIV&gt; remark SDM_ACL Category=128&lt;/DIV&gt;&lt;DIV&gt; permit ip 192.0.0.0 0.255.255.255 any&lt;/DIV&gt;&lt;DIV&gt; permit ip 10.xxx.xxx0 0.0.255.255 any&lt;/DIV&gt;&lt;DIV&gt;ip access-list extended SDM_HTTPS&lt;/DIV&gt;&lt;DIV&gt; remark SDM_ACL Category=1&lt;/DIV&gt;&lt;DIV&gt; permit tcp any any eq 443&lt;/DIV&gt;&lt;DIV&gt;ip access-list extended SDM_SHELL&lt;/DIV&gt;&lt;DIV&gt; remark SDM_ACL Category=1&lt;/DIV&gt;&lt;DIV&gt; permit tcp any any eq cmd&lt;/DIV&gt;&lt;DIV&gt;ip access-list extended SDM_SSH&lt;/DIV&gt;&lt;DIV&gt; remark SDM_ACL Category=1&lt;/DIV&gt;&lt;DIV&gt; permit tcp any any eq 22&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;access-list 1 remark INSIDE_IF=Vlan1&lt;/DIV&gt;&lt;DIV&gt;access-list 1 remark SDM_ACL Category=2&lt;/DIV&gt;&lt;DIV&gt;access-list 1 permit 172.18.1.0 0.0.0.255&lt;/DIV&gt;&lt;DIV&gt;access-list 100 permit tcp any any eq 3389&lt;/DIV&gt;&lt;DIV&gt;access-list 101 remark SDM_ACL Category=4&lt;/DIV&gt;&lt;DIV&gt;access-list 101 remark IPSec Rule&lt;/DIV&gt;&lt;DIV&gt;access-list 101 permit ip 172.18.1.0 0.0.0.255 172.18.2.0 0.0.0.255&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;access-list 106 remark SDM_ACL Category=128&lt;/DIV&gt;&lt;DIV&gt;access-list 106 permit ip host 255.255.255.255 any&lt;/DIV&gt;&lt;DIV&gt;access-list 106 permit ip 127.0.0.0 0.255.255.255 any&lt;/DIV&gt;&lt;DIV&gt;access-list 106 permit ip 190.xxx.xxx.56 0.0.0.7 any&lt;/DIV&gt;&lt;DIV&gt;access-list 106 permit ip 192.0.0.0 0.255.255.255 any&lt;/DIV&gt;&lt;DIV&gt;access-list 106 permit ip 10.xxx.xxx.0 0.0.255.255 any&lt;/DIV&gt;&lt;DIV&gt;access-list 106 permit ip host 200.xxx.xxx.149 any&amp;nbsp;&amp;nbsp;&amp;nbsp; (PRINTER HOST)&lt;/DIV&gt;&lt;DIV&gt;access-list 106 permit ip any host 200.xxx.xxx.149&amp;nbsp;&amp;nbsp;&amp;nbsp; (PRINTER HOST)&lt;/DIV&gt;&lt;DIV&gt;snmp-server community asaro RO&lt;/DIV&gt;&lt;DIV&gt;no cdp run&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;route-map SDM_RMAP_1 permit 1&lt;/DIV&gt;&lt;DIV&gt; match ip address 102&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;control-plane&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;banner login ^CCAuthorized access only!&lt;/DIV&gt;&lt;DIV&gt; Disconnect IMMEDIATELY if you are not an authorized user!^C&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;line con 0&lt;/DIV&gt;&lt;DIV&gt; transport output telnet&lt;/DIV&gt;&lt;DIV&gt;line aux 0&lt;/DIV&gt;&lt;DIV&gt; transport output telnet&lt;/DIV&gt;&lt;DIV&gt;line vty 0 4&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;end&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:23:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-smtp-on-firewall-cisco-1800/m-p/1599414#M587100</guid>
      <dc:creator>andresitotubia</dc:creator>
      <dc:date>2019-03-11T19:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: Enable SMTP on firewall cisco 1800</title>
      <link>https://community.cisco.com/t5/network-security/enable-smtp-on-firewall-cisco-1800/m-p/1599415#M587101</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; you have in your voice class:&lt;/P&gt;&lt;P&gt;match protocol smtp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the firewall is actively inspecting smtp, it could be finding something it didn't like in your smtp traffic. so enable:&lt;/P&gt;&lt;P&gt;ip inspect log drop-pkt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then check the router logs for the smtp traffic and see why it's dropping it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Fadi.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Dec 2010 21:18:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-smtp-on-firewall-cisco-1800/m-p/1599415#M587101</guid>
      <dc:creator>fadlouni</dc:creator>
      <dc:date>2010-12-20T21:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: Enable SMTP on firewall cisco 1800</title>
      <link>https://community.cisco.com/t5/network-security/enable-smtp-on-firewall-cisco-1800/m-p/1599416#M587103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;EM&gt;zone-pair security sdm-zp-in-out source in-zone destination out-zone&lt;/EM&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;EM&gt; service-policy type inspect sdm-inspect&lt;/EM&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV&gt;you are applying this policy from in to out and you are inspecting smtp so only return traffic from out to in is allowed.&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV&gt;If you want access from outside then you must apply separate policy for your smtp from out to in.&lt;/DIV&gt;&lt;DIV&gt;and get rid of match smtp in your class voice as it will be in a new class now.&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV&gt;Regards.&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV&gt;Alain.&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Dec 2010 08:50:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-smtp-on-firewall-cisco-1800/m-p/1599416#M587103</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2010-12-21T08:50:27Z</dc:date>
    </item>
  </channel>
</rss>

