<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cannot pass smtp - 25 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-pass-smtp-25/m-p/1033586#M916116</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what software version of the PIX do you have?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 Jul 2008 18:56:37 GMT</pubDate>
    <dc:creator>a.alekseev</dc:creator>
    <dc:date>2008-07-23T18:56:37Z</dc:date>
    <item>
      <title>cannot pass smtp - 25</title>
      <link>https://community.cisco.com/t5/network-security/cannot-pass-smtp-25/m-p/1033585#M916115</link>
      <description>&lt;P&gt;515E&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am in the process of setting up an in house mail server. In so I have setup smtp, pop3, and imap to pass to my mail server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for some reason when I do the telnet test for 25 from an outside location, the 515E returns the 220 and not my mail server. pop3 and imap seem to work fine&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any ideas what could be blocking my 25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;mark&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:19:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-pass-smtp-25/m-p/1033585#M916115</guid>
      <dc:creator>mjackson</dc:creator>
      <dc:date>2019-03-11T13:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: cannot pass smtp - 25</title>
      <link>https://community.cisco.com/t5/network-security/cannot-pass-smtp-25/m-p/1033586#M916116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what software version of the PIX do you have?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jul 2008 18:56:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-pass-smtp-25/m-p/1033586#M916116</guid>
      <dc:creator>a.alekseev</dc:creator>
      <dc:date>2008-07-23T18:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: cannot pass smtp - 25</title>
      <link>https://community.cisco.com/t5/network-security/cannot-pass-smtp-25/m-p/1033587#M916117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mark,&lt;/P&gt;&lt;P&gt;  "the 515E returns the 220 and not my mail server"&lt;/P&gt;&lt;P&gt;  I dont know a reply type of "220" from PIX firewall. If you telnet 25 to the IP and get any kind of screen (either blank or some output) other than "Could not open connection to the host" Connect failed or timeout, that means the port is open.&lt;/P&gt;&lt;P&gt;  By the way, exchange server reply to a telnet to port 25 starts with 220. Here is one of them&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"220 xxxx.xxxx.xxx Microsoft ESMTP MAIL Service, Version: 6.0.3790.3959 ready at&lt;/P&gt;&lt;P&gt;  Wed, 23 Jul 2008 23:09:19 +0300 "&lt;/P&gt;&lt;P&gt;  Or sometimes just 220 and some ASCII chars like ######## or so.&lt;/P&gt;&lt;P&gt;  If you post your sanitized config, we would help better.&lt;/P&gt;&lt;P&gt;  Also make sure that you configued your SMTP Connector in Exchange server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jul 2008 19:07:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-pass-smtp-25/m-p/1033587#M916117</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-07-23T19:07:01Z</dc:date>
    </item>
    <item>
      <title>Re: cannot pass smtp - 25</title>
      <link>https://community.cisco.com/t5/network-security/cannot-pass-smtp-25/m-p/1033588#M916118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You probably also want to turnoff fixup for smtp.  We run a 515e and E2K and have it off.  It's my understanding that MS has a problem with that.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jul 2008 19:31:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-pass-smtp-25/m-p/1033588#M916118</guid>
      <dc:creator>paulc</dc:creator>
      <dc:date>2008-07-23T19:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: cannot pass smtp - 25</title>
      <link>https://community.cisco.com/t5/network-security/cannot-pass-smtp-25/m-p/1033589#M916119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Guessing old, I inherited this when I started this job.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;version 6.3(5) does that sound right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jul 2008 19:39:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-pass-smtp-25/m-p/1033589#M916119</guid>
      <dc:creator>mjackson</dc:creator>
      <dc:date>2008-07-23T19:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: cannot pass smtp - 25</title>
      <link>https://community.cisco.com/t5/network-security/cannot-pass-smtp-25/m-p/1033590#M916120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;when I do the telnet 25 from an outside location I get one of 2 returns&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;220 ####### - I am told this is the 515e responding&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or  nothing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jul 2008 19:43:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-pass-smtp-25/m-p/1033590#M916120</guid>
      <dc:creator>mjackson</dc:creator>
      <dc:date>2008-07-23T19:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: cannot pass smtp - 25</title>
      <link>https://community.cisco.com/t5/network-security/cannot-pass-smtp-25/m-p/1033591#M916121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In this case I advise you to turn off smtp fixup. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jul 2008 19:48:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-pass-smtp-25/m-p/1033591#M916121</guid>
      <dc:creator>a.alekseev</dc:creator>
      <dc:date>2008-07-23T19:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: cannot pass smtp - 25</title>
      <link>https://community.cisco.com/t5/network-security/cannot-pass-smtp-25/m-p/1033592#M916122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mark,&lt;/P&gt;&lt;P&gt;"220 ####### - I am told this is the 515e responding" &lt;/P&gt;&lt;P&gt;  Inspection is replacing the starttls echo-reply with ## sometimes ** . Most mail servers work in this case, but your mail server may not be able to establish connection with some mail servers. &lt;/P&gt;&lt;P&gt;  Following are the necessary commands to correct that&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect esmtp esmtp_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;  no mask-banner&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;inspect esmtp esmtp_map&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   But this is available in code 7.2 or higher. I dont know an equivalant for 6.3 code and I assume it does not exist.&lt;/P&gt;&lt;P&gt;   Better upgrade your IOS or remove the fixup as suggested.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jul 2008 00:04:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-pass-smtp-25/m-p/1033592#M916122</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-07-24T00:04:33Z</dc:date>
    </item>
  </channel>
</rss>

