<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT outbound SMTP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-outbound-smtp/m-p/1481090#M726889</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It worked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you Bhisham&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 May 2010 23:24:59 GMT</pubDate>
    <dc:creator>zulu-5-2010</dc:creator>
    <dc:date>2010-05-06T23:24:59Z</dc:date>
    <item>
      <title>NAT outbound SMTP</title>
      <link>https://community.cisco.com/t5/network-security/nat-outbound-smtp/m-p/1481087#M726886</link>
      <description>&lt;P&gt;Ladies and Gents,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 3 interfaces in my PIX, Inside, Public and DMZ. I have a host (192.168.1.111) in the DMZ that needs to relay mail to a smart host on the internet. However, the smart host only accepts connections from certain addresses. Public interface's address is one of them. So I've set up an ACL, applied it to the interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit tcp host 192.168.1.111 eq smtp object-group smarthostcluster eq smtp&lt;/P&gt;&lt;P&gt;access-group DMZ_access_in in interface DMZ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I have to NAT/PAT the traffic, since the smart host only accepts connections from the Public interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (Public) 1 interface&lt;/P&gt;&lt;P&gt;nat (DMZ) 1 192.168.1.111 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, it still doesn't work. It says connection is refused. So, I wonder if I have missed something. Our main server sends out fine, but the Inside ACL is a lot less restrictive so I really don't know who's at fault, me or the smart host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Igs&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:40:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-outbound-smtp/m-p/1481087#M726886</guid>
      <dc:creator>zulu-5-2010</dc:creator>
      <dc:date>2019-03-11T17:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: NAT outbound SMTP</title>
      <link>https://community.cisco.com/t5/network-security/nat-outbound-smtp/m-p/1481088#M726887</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;access-list DMZ_access_in extended permit tcp host 192.168.1.111 object-group smarthostcluster eq smtp&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;access-group DMZ_access_in in interface DMZ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I have to NAT/PAT the traffic, since the smart host only accepts connections from the Public interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (Public) 1 interface&lt;/P&gt;&lt;P&gt;nat (DMZ) 1 192.168.1.111 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try this hope this will work...!&lt;/P&gt;&lt;P&gt;Thanks/Bhisham&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 May 2010 06:50:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-outbound-smtp/m-p/1481088#M726887</guid>
      <dc:creator>bhisham84</dc:creator>
      <dc:date>2010-05-04T06:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: NAT outbound SMTP</title>
      <link>https://community.cisco.com/t5/network-security/nat-outbound-smtp/m-p/1481089#M726888</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bhisham, thank you for your help. Greatly appriciated.&lt;/P&gt;&lt;P&gt;I'll change the line tomorrow, see what happens&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 May 2010 06:55:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-outbound-smtp/m-p/1481089#M726888</guid>
      <dc:creator>zulu-5-2010</dc:creator>
      <dc:date>2010-05-04T06:55:39Z</dc:date>
    </item>
    <item>
      <title>Re: NAT outbound SMTP</title>
      <link>https://community.cisco.com/t5/network-security/nat-outbound-smtp/m-p/1481090#M726889</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It worked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you Bhisham&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 May 2010 23:24:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-outbound-smtp/m-p/1481090#M726889</guid>
      <dc:creator>zulu-5-2010</dc:creator>
      <dc:date>2010-05-06T23:24:59Z</dc:date>
    </item>
  </channel>
</rss>

