<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5505 LDAP Sync for GFI Max Mail Protection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5505-ldap-sync-for-gfi-max-mail-protection/m-p/1508709#M611850</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The GFI name entries are subnets and not hosts, maybe this&lt;/P&gt;&lt;P&gt; is the cause.&lt;/P&gt;&lt;P&gt;E.g. GFI1 is 208.80.78.0 for example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would I need to simply add a "mask" entry or is this irrelevant ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;S.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 10 Sep 2010 14:19:07 GMT</pubDate>
    <dc:creator>stephenwilletts</dc:creator>
    <dc:date>2010-09-10T14:19:07Z</dc:date>
    <item>
      <title>ASA 5505 LDAP Sync for GFI Max Mail Protection</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ldap-sync-for-gfi-max-mail-protection/m-p/1508705#M611846</link>
      <description>&lt;P&gt;Having great trouble trying to get my online mail filtering service to sync with LDAP through the Cisco ASA 5505.&lt;/P&gt;&lt;P&gt;Please below for firewall entries.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;access-list outside extended permit tcp host GFI1 host SMTP eq ldap&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 10pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;static (inside,outside) tcp SMTP ldap SERVER ldap netmask 255.255.255.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The below error gets logged on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Deny tcp src outside:208.70.89.81/42946 dst inside:SMTP/389 by access-group "outside" [0x0, 0x0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have I done something wrong or missing some config entries ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The server is SBS2008 with LDS installed and configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;S.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:38:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ldap-sync-for-gfi-max-mail-protection/m-p/1508705#M611846</guid>
      <dc:creator>stephenwilletts</dc:creator>
      <dc:date>2019-03-11T18:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 LDAP Sync for GFI Max Mail Protection</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ldap-sync-for-gfi-max-mail-protection/m-p/1508706#M611847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Stephen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What IP address is configured assigned to the GFI1 name? You can check 'show run name | i GFI1' to see if it is configured for 208.70.89.81.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Sep 2010 14:03:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ldap-sync-for-gfi-max-mail-protection/m-p/1508706#M611847</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2010-09-10T14:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 LDAP Sync for GFI Max Mail Protection</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ldap-sync-for-gfi-max-mail-protection/m-p/1508707#M611848</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've a number of GFIx names assigned to a number of their IP ranges and all are OK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;S.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Sep 2010 14:12:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ldap-sync-for-gfi-max-mail-protection/m-p/1508707#M611848</guid>
      <dc:creator>stephenwilletts</dc:creator>
      <dc:date>2010-09-10T14:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 LDAP Sync for GFI Max Mail Protection</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ldap-sync-for-gfi-max-mail-protection/m-p/1508708#M611849</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Stephen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But does the "outside" access list contain a rule that permits traffic sourced from 208.70.89.81 and destined to the host called SMTP on port 389? The log message you see indicates that the packet isn't matching any of the permit rules in the access list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Sep 2010 14:14:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ldap-sync-for-gfi-max-mail-protection/m-p/1508708#M611849</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2010-09-10T14:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 LDAP Sync for GFI Max Mail Protection</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ldap-sync-for-gfi-max-mail-protection/m-p/1508709#M611850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The GFI name entries are subnets and not hosts, maybe this&lt;/P&gt;&lt;P&gt; is the cause.&lt;/P&gt;&lt;P&gt;E.g. GFI1 is 208.80.78.0 for example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would I need to simply add a "mask" entry or is this irrelevant ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;S.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Sep 2010 14:19:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ldap-sync-for-gfi-max-mail-protection/m-p/1508709#M611850</guid>
      <dc:creator>stephenwilletts</dc:creator>
      <dc:date>2010-09-10T14:19:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 LDAP Sync for GFI Max Mail Protection</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ldap-sync-for-gfi-max-mail-protection/m-p/1508710#M611851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Stephen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Names are only used for hosts, so they don't accept a subnet mask. In the example you provided, the ASA will try to match the packet to 208.80.78.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to specify full subnets, you can use object-groups:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network GFI1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; network-object 208.80.78.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You'll also need to adjust your access-list to use the object-group like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside extended permit tcp object-group GFI1 host SMTP eq ldap&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Sep 2010 14:27:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ldap-sync-for-gfi-max-mail-protection/m-p/1508710#M611851</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2010-09-10T14:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 LDAP Sync for GFI Max Mail Protection</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ldap-sync-for-gfi-max-mail-protection/m-p/1508711#M611852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This got it working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many many thanks.&lt;/P&gt;&lt;P&gt;S.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Sep 2010 15:50:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ldap-sync-for-gfi-max-mail-protection/m-p/1508711#M611852</guid>
      <dc:creator>stephenwilletts</dc:creator>
      <dc:date>2010-09-10T15:50:20Z</dc:date>
    </item>
  </channel>
</rss>

