<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Replaced ASA &amp; E-mail in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/replaced-asa-e-mail/m-p/1441501#M739503</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HMidkiff,&lt;/P&gt;&lt;P&gt;I am not sure which source IP sent this NDR and to which destination IP.&amp;nbsp; I am thinking that your e-mail server tried to deliver messages not looking like the MX record so, the receiving MTA didn't accept it. This could have had something to do with translation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any time you replace a unit (move the cables between units) and keep the IP addresses you should clear the upstream router's cache. If you shut the old PIX then, plug the cables on the ASA and then power it on, it should have proxy arp-ed and the router would have updated its arp cache.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 09 Aug 2010 13:28:50 GMT</pubDate>
    <dc:creator>Kureli Sankar</dc:creator>
    <dc:date>2010-08-09T13:28:50Z</dc:date>
    <item>
      <title>Replaced ASA &amp; E-mail</title>
      <link>https://community.cisco.com/t5/network-security/replaced-asa-e-mail/m-p/1441500#M739502</link>
      <description>&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: &amp;amp;quot;Arial&amp;amp;quot;, &amp;amp;quot;sans-serif&amp;amp;quot;; color: #333333; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Hello:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: &amp;amp;quot;Arial&amp;amp;quot;, &amp;amp;quot;sans-serif&amp;amp;quot;; color: #333333; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: &amp;amp;quot;Arial&amp;amp;quot;, &amp;amp;quot;sans-serif&amp;amp;quot;; color: #333333; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;This may not be the right forum for this, but over the weekend I tried to replace my PIX515e with a new ASA5520.&amp;nbsp; I got it online and then right away in testing when sending outbound e-mails I got the below NDR.&amp;nbsp; I use Exchange.&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;It goes Back End to Front End and then forwarded to a delivery service (ProofPoint).&amp;nbsp;&amp;nbsp; I assumed if I would have had delivery problems messages would just have queued up rather than users getting an NDR.&amp;nbsp;&amp;nbsp; After unsuccessfully trying to resolve the issue I had to revert back to the PIX515e.&amp;nbsp; When I did that I was not getting NDR's anymore, but NAT's and e-mail were not working.&amp;nbsp;&amp;nbsp; I ended up flushing the ARP cache on my upstream router and then everything returned to normal.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: &amp;amp;quot;Arial&amp;amp;quot;, &amp;amp;quot;sans-serif&amp;amp;quot;; color: #333333; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: &amp;amp;quot;Arial&amp;amp;quot;, &amp;amp;quot;sans-serif&amp;amp;quot;; color: #333333; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;Could a bad ARP entries on my upstream router caused NDR's like what I saw?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: &amp;amp;quot;Arial&amp;amp;quot;, &amp;amp;quot;sans-serif&amp;amp;quot;; color: #333333; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: &amp;amp;quot;Arial&amp;amp;quot;, &amp;amp;quot;sans-serif&amp;amp;quot;; color: #333333; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: &amp;amp;quot;Arial&amp;amp;quot;, &amp;amp;quot;sans-serif&amp;amp;quot;; color: #333333; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: &amp;amp;quot;Arial&amp;amp;quot;, &amp;amp;quot;sans-serif&amp;amp;quot;; color: #333333; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt;*******************&amp;nbsp;&amp;nbsp; NDR&amp;nbsp;&amp;nbsp; *******************&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Consolas; color: black; font-size: 10.5pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Consolas;"&gt;Your message did not reach some or all of the intended recipients.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="text-indent: -1in; margin: 0in 0in 0pt 1in; tab-stops: 1.0in; mso-layout-grid-align: none;"&gt;&lt;SPAN style="font-family: Consolas; color: #333333; font-size: 10.5pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Consolas;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="text-indent: -1in; margin: 0in 0in 0pt 1in; tab-stops: 1.0in; mso-layout-grid-align: none;"&gt;&lt;SPAN style="font-family: Consolas; color: black; font-size: 10.5pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Consolas;"&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Subject:&lt;SPAN style="mso-tab-count: 1;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;How are you&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="text-indent: -1in; margin: 0in 0in 0pt 1in; tab-stops: 1.0in; mso-layout-grid-align: none;"&gt;&lt;SPAN style="font-family: Consolas; color: black; font-size: 10.5pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Consolas;"&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Sent:&lt;SPAN style="mso-tab-count: 1;"&gt; &lt;/SPAN&gt;8/8/2010 3:54 PM&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-layout-grid-align: none;"&gt;&lt;SPAN style="font-family: Consolas; color: #333333; font-size: 10.5pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Consolas;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-layout-grid-align: none;"&gt;&lt;SPAN style="font-family: Consolas; color: black; font-size: 10.5pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Consolas;"&gt;The following recipient(s) cannot be reached:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-layout-grid-align: none;"&gt;&lt;SPAN style="font-family: Consolas; color: #333333; font-size: 10.5pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Consolas;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-layout-grid-align: none;"&gt;&lt;SPAN style="mso-bidi-font-family: Consolas; color: black; font-size: 10.5pt; mso-spacerun: yes; font-family: Consolas; mso-fareast-font-family: 'Times New Roman'; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-family: Consolas; color: #333333; font-size: 10.5pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Consolas;"&gt;&lt;A href="mailto:hxyz@gmail.com" target="_blank"&gt;&lt;SPAN style="color: blue; mso-bidi-font-size: 11.0pt;"&gt;xyz@gmail.com&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: Consolas; color: black; font-size: 10.5pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Consolas;"&gt; on 8/8/2010 3:54 PM&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-layout-grid-align: none;"&gt;&lt;SPAN style="font-family: Consolas; color: black; font-size: 10.5pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Consolas;"&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;You do not have permission to send to this recipient.&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;For assistance, contact your system administrator.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-layout-grid-align: none;"&gt;&lt;SPAN style="font-family: Consolas; color: black; font-size: 10.5pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Consolas;"&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&amp;lt;SERVER.DOMAIN.COM #5.7.1 smtp;550 5.7.1 Unable to relay for xyz&lt;/SPAN&gt;&lt;SPAN style="font-family: Consolas; color: #333333; font-size: 10.5pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Consolas;"&gt;&lt;A href="mailto:h@gmail.com" target="_blank"&gt;&lt;SPAN style="color: blue; mso-bidi-font-size: 11.0pt;"&gt;@gmail.com&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: Consolas; color: black; font-size: 10.5pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Consolas;"&gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-layout-grid-align: none;"&gt;&lt;SPAN style="font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;, &amp;amp;quot;serif&amp;amp;quot;; color: #333333; font-size: 12pt; mso-fareast-font-family: 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-layout-grid-align: none;"&gt;&lt;SPAN style="font-family: Consolas; color: black; font-size: 10.5pt; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Consolas;"&gt;Harrison Midkiff&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: &amp;amp;quot;Arial&amp;amp;quot;, &amp;amp;quot;sans-serif&amp;amp;quot;; color: #333333; font-size: 10pt; mso-fareast-font-family: 'Times New Roman';"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:22:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replaced-asa-e-mail/m-p/1441500#M739502</guid>
      <dc:creator>HMidkiff</dc:creator>
      <dc:date>2019-03-11T18:22:38Z</dc:date>
    </item>
    <item>
      <title>Re: Replaced ASA &amp; E-mail</title>
      <link>https://community.cisco.com/t5/network-security/replaced-asa-e-mail/m-p/1441501#M739503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HMidkiff,&lt;/P&gt;&lt;P&gt;I am not sure which source IP sent this NDR and to which destination IP.&amp;nbsp; I am thinking that your e-mail server tried to deliver messages not looking like the MX record so, the receiving MTA didn't accept it. This could have had something to do with translation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any time you replace a unit (move the cables between units) and keep the IP addresses you should clear the upstream router's cache. If you shut the old PIX then, plug the cables on the ASA and then power it on, it should have proxy arp-ed and the router would have updated its arp cache.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Aug 2010 13:28:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replaced-asa-e-mail/m-p/1441501#M739503</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-08-09T13:28:50Z</dc:date>
    </item>
  </channel>
</rss>

