<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA and inspect esmtp in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-and-inspect-esmtp/m-p/1263350#M763807</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly understand the functionality of 'inspect esmtp' first. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please visit the following link for information on the same:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/i2.html#wp1719425" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/i2.html#wp1719425&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming the receiving MTA is indicating that it supports Binary Chunking, and that implies that the binary data (BDAT) verb is also supported.  However, the ASA does not support the BDAT verb and will XXXX it out.  When the receiving MTA gets the Xed out command, it will send back a 500 (Unrecognized command) to the sending MTA.  The sending MTA (in the case of Microsoft) then Resets (RSET) the connection.  This causes mails to be unable to be sent.  The problem here is with the ASA.  This can be clearly seen by applying captures on the outside interface of the firewall with an error code of 500. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To rectify this please make a custom esmtp policy map like one configured in the below given example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect esmtp _default_esmtp_map&lt;/P&gt;&lt;P&gt;match ehlo-reply-parameter others&lt;/P&gt;&lt;P&gt;  mask&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please apply this policy map on the outside interface. This will ensure esmtp inspection being turned on and also allowing BDAT connection to pass through the firewall masking them instead of Xing them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;P&gt;Manish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Nov 2009 23:36:56 GMT</pubDate>
    <dc:creator>mkharban</dc:creator>
    <dc:date>2009-11-05T23:36:56Z</dc:date>
    <item>
      <title>ASA and inspect esmtp</title>
      <link>https://community.cisco.com/t5/network-security/asa-and-inspect-esmtp/m-p/1263349#M763805</link>
      <description>&lt;P&gt;Our ASA is running code 8.0.4 and our smtp mail inbound and outbound working fine, then it was broken.  Check the ASA and the inspect esmtp is on by default and this working before.  The mail library was updated and nothing is working.  Researched and found out that by removing inspect esmtp and mail is working again.  I would like to keep the inspect esmtp on for security purpose but need to find a work around solution.  Please let me know if there is a work around for this.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:36:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-and-inspect-esmtp/m-p/1263349#M763805</guid>
      <dc:creator>ttran</dc:creator>
      <dc:date>2019-03-11T16:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA and inspect esmtp</title>
      <link>https://community.cisco.com/t5/network-security/asa-and-inspect-esmtp/m-p/1263350#M763807</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly understand the functionality of 'inspect esmtp' first. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please visit the following link for information on the same:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/i2.html#wp1719425" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/i2.html#wp1719425&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming the receiving MTA is indicating that it supports Binary Chunking, and that implies that the binary data (BDAT) verb is also supported.  However, the ASA does not support the BDAT verb and will XXXX it out.  When the receiving MTA gets the Xed out command, it will send back a 500 (Unrecognized command) to the sending MTA.  The sending MTA (in the case of Microsoft) then Resets (RSET) the connection.  This causes mails to be unable to be sent.  The problem here is with the ASA.  This can be clearly seen by applying captures on the outside interface of the firewall with an error code of 500. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To rectify this please make a custom esmtp policy map like one configured in the below given example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect esmtp _default_esmtp_map&lt;/P&gt;&lt;P&gt;match ehlo-reply-parameter others&lt;/P&gt;&lt;P&gt;  mask&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please apply this policy map on the outside interface. This will ensure esmtp inspection being turned on and also allowing BDAT connection to pass through the firewall masking them instead of Xing them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;P&gt;Manish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 23:36:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-and-inspect-esmtp/m-p/1263350#M763807</guid>
      <dc:creator>mkharban</dc:creator>
      <dc:date>2009-11-05T23:36:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA and inspect esmtp</title>
      <link>https://community.cisco.com/t5/network-security/asa-and-inspect-esmtp/m-p/1263351#M763810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Manish,&lt;/P&gt;&lt;P&gt;You are certainly helping alot and thank you for the link and this is good.  Just to clear my confusing since I read so many different documents so I will keep the inspect esmtp on the global policy and add the custom esmtp as in the example or remove the the inspect esmtp and add the custom esmtp.  Please let me know.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 14:48:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-and-inspect-esmtp/m-p/1263351#M763810</guid>
      <dc:creator>ttran</dc:creator>
      <dc:date>2009-11-06T14:48:29Z</dc:date>
    </item>
    <item>
      <title>Re: ASA and inspect esmtp</title>
      <link>https://community.cisco.com/t5/network-security/asa-and-inspect-esmtp/m-p/1263352#M763811</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We will have to keep only the custom inspection turned on in order to get this working. Kindly apply the same and let me know how it goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Manish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 17:28:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-and-inspect-esmtp/m-p/1263352#M763811</guid>
      <dc:creator>mkharban</dc:creator>
      <dc:date>2009-11-06T17:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA and inspect esmtp</title>
      <link>https://community.cisco.com/t5/network-security/asa-and-inspect-esmtp/m-p/1263353#M763812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Manish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for verification.  I will apply the custom inspection like your example.  Just a note on the policy-map the esmtp after the word inspect should not have the underscore to default correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 18:01:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-and-inspect-esmtp/m-p/1263353#M763812</guid>
      <dc:creator>ttran</dc:creator>
      <dc:date>2009-11-06T18:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASA and inspect esmtp</title>
      <link>https://community.cisco.com/t5/network-security/asa-and-inspect-esmtp/m-p/1263354#M763814</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can alter the name according to yourself. I just stated that as an example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Manish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Nov 2009 18:45:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-and-inspect-esmtp/m-p/1263354#M763814</guid>
      <dc:creator>mkharban</dc:creator>
      <dc:date>2009-11-06T18:45:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA and inspect esmtp</title>
      <link>https://community.cisco.com/t5/network-security/asa-and-inspect-esmtp/m-p/1263355#M763816</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Manish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is working. Thank you. 5 for you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Nov 2009 14:52:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-and-inspect-esmtp/m-p/1263355#M763816</guid>
      <dc:creator>ttran</dc:creator>
      <dc:date>2009-11-10T14:52:53Z</dc:date>
    </item>
  </channel>
</rss>

