<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dear Sandy, Kindly find the in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/exchange-server-using-interface-ip-after-migrating-from-8-2-to-9/m-p/2450139#M934727</link>
    <description>&lt;P&gt;Dear Sandy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly find the below below information as you requested.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 27 May 2014 07:39:00 GMT</pubDate>
    <dc:creator>najeeb_v</dc:creator>
    <dc:date>2014-05-27T07:39:00Z</dc:date>
    <item>
      <title>exchange server using interface IP after migrating from 8.2 to 9.1</title>
      <link>https://community.cisco.com/t5/network-security/exchange-server-using-interface-ip-after-migrating-from-8-2-to-9/m-p/2450131#M934706</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;i recently upgraded an ASA pair from 5510 (ASA OS 8.2) to 5512 (ASA OS 9.1). Many of the services are working fine including VPN after some tweaking and modifications in the new configuration, however the exchange server is not sending the traffic from its designated public IP which is mentioned in NAT statements. Exchange is using the public interface IP of the firewall for outbound communication. If i try to telnet from outside to the public IP addresses of the exchange server its giving proper response. kindly help me with this issue. i believe this is some NAT related issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OLD configuration (relevant part only)&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;access-list out_in extended permit tcp any host 213.42.201.35 eq www&amp;nbsp;&lt;BR /&gt;access-list out_in extended permit tcp any host 213.42.201.35 eq https&lt;BR /&gt;access-list out_in extended permit icmp any host 213.42.201.35&lt;BR /&gt;access-list out_in extended permit tcp any host 213.42.201.35 eq smtp&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;static (DMZ,outside) tcp 213.42.201.35 www 172.16.2.200 www netmask 255.255.255.255&lt;BR /&gt;static (inside,outside) tcp 213.42.201.35 https 192.168.190.57 https netmask 255.255.255.255&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;static (DMZ,outside) 213.42.201.35 172.16.2.11 netmask 255.255.255.255&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;access-list out_in extended permit tcp any host 213.42.201.34 eq smtp&amp;nbsp;&lt;BR /&gt;static (DMZ,outside) 213.42.201.34 172.16.2.21 netmask 255.255.255.255&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;New Configuraion&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;object network obj-172.16.2.21&lt;BR /&gt;&amp;nbsp;host 172.16.2.21&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;&amp;nbsp;description Created during name migration&lt;BR /&gt;object network obj-172.16.2.11&lt;BR /&gt;&amp;nbsp;host 172.16.2.11&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;access-list out_in extended permit icmp any host 172.16.2.11&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;access-list out_in extended permit tcp any host 172.16.2.11 eq smtp&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;access-list out_in extended permit tcp any host 172.16.2.21 eq smtp&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace; font-size: 11px;"&gt;nat (inside,outside) static 213.42.201.35 service tcp https https&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;object network obj-192.168.0.0&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic interface dns&lt;BR /&gt;object network obj-192.168.0.0-01&lt;BR /&gt;&amp;nbsp;nat (inside,DMZ) dynamic 172.16.2.254 dns&lt;BR /&gt;object network obj_any&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic obj-0.0.0.0&lt;BR /&gt;object network obj_any-01&lt;BR /&gt;&amp;nbsp;nat (inside,DMZ) dynamic obj-0.0.0.0&lt;BR /&gt;object network obj-172.16.2.21&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;&amp;nbsp;nat (DMZ,outside) static 213.42.201.34&lt;BR /&gt;object network obj-172.16.2.11&lt;BR /&gt;&amp;nbsp;nat (DMZ,outside) static 213.42.201.35 service tcp smtp smtp&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Najeeb&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:11:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/exchange-server-using-interface-ip-after-migrating-from-8-2-to-9/m-p/2450131#M934706</guid>
      <dc:creator>najeeb_v</dc:creator>
      <dc:date>2020-02-21T13:11:41Z</dc:date>
    </item>
    <item>
      <title>Hi Najeeb , I do see two</title>
      <link>https://community.cisco.com/t5/network-security/exchange-server-using-interface-ip-after-migrating-from-8-2-to-9/m-p/2450132#M934707</link>
      <description>&lt;P&gt;Hi Najeeb ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;I do see two different public IP address&amp;nbsp;&lt;SPAN style="font-family: 'courier new', courier, monospace; font-size: 11px;"&gt;213.42.201.34 ,&amp;nbsp;213.42.201.35 .&amp;nbsp;&lt;/SPAN&gt;which IP address you are able to reach from internet ??&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; If understand your problem correctly , from internet you can telnet to this Public IP address 213.42.201.35 on port 25 ??&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;SPAN style="font-family: 'courier new', courier, monospace; font-size: 11px;"&gt;object network obj-172.16.2.11&lt;/SPAN&gt;&lt;BR style="font-family: 'courier new', courier, monospace; font-size: 11px;" /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace; font-size: 11px;"&gt;&amp;nbsp;nat (DMZ,outside) static 213.42.201.35 service tcp smtp smtp&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Sandy&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2014 07:28:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/exchange-server-using-interface-ip-after-migrating-from-8-2-to-9/m-p/2450132#M934707</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2014-05-22T07:28:59Z</dc:date>
    </item>
    <item>
      <title>Dear Santhosh thanks for the</title>
      <link>https://community.cisco.com/t5/network-security/exchange-server-using-interface-ip-after-migrating-from-8-2-to-9/m-p/2450133#M934708</link>
      <description>&lt;P&gt;Dear Santhosh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for the quick update, yes i am able to telnet to both public IP addresses assigned for the exchange servers (i.e 213.42.201.34 &amp;amp; 35) on ports 25. The issue is exchange is sending the outgoing traffic via the outside interface of my firewall (213.42.201.46). My gut feeling is it has something to do with the new NAT statements. if you need more info regards to this kindly let me know&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Najeeb&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2014 07:50:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/exchange-server-using-interface-ip-after-migrating-from-8-2-to-9/m-p/2450133#M934708</guid>
      <dc:creator>najeeb_v</dc:creator>
      <dc:date>2014-05-22T07:50:18Z</dc:date>
    </item>
    <item>
      <title>Dear Santosh correction, i am</title>
      <link>https://community.cisco.com/t5/network-security/exchange-server-using-interface-ip-after-migrating-from-8-2-to-9/m-p/2450134#M934709</link>
      <description>&lt;P&gt;Dear Santosh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;correction, i am not able to telnet to the public IPs with port 25, but if i do a MXtoolbox portscan i can see ports 25 and 443 responding to the request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Najeeb&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2014 07:54:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/exchange-server-using-interface-ip-after-migrating-from-8-2-to-9/m-p/2450134#M934709</guid>
      <dc:creator>najeeb_v</dc:creator>
      <dc:date>2014-05-22T07:54:59Z</dc:date>
    </item>
    <item>
      <title>Hi Najeeb, If  you are able</title>
      <link>https://community.cisco.com/t5/network-security/exchange-server-using-interface-ip-after-migrating-from-8-2-to-9/m-p/2450135#M934710</link>
      <description>&lt;P&gt;Hi Najeeb,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;SPAN style="font-size: 14px; font-family: 'comic sans ms', cursive;"&gt;If &amp;nbsp;you are able to reach out to your SMTP via Public IP address , 172.16.2.11 will be using public IP address 213.42.201.35 for mail delivery (SMTP service alone) . Server 172.16.2.21 will be using Public IP address 213.42.201.34&lt;/SPAN&gt;&lt;SPAN style="font-size: 14px; font-family: 'comic sans ms', cursive;"&gt;&amp;nbsp;for any traffic including SMTP , to double check this open your IE on your 172.16.2.21 google it for what is my IP address , you will see your public ip address 213.42.201.34 on your google results .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="comic sans ms, cursive"&gt;&lt;SPAN style="font-size: 14px;"&gt;At any point time your both server will never use your outside interface for any&amp;nbsp;external&amp;nbsp;communication&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 14px; background-color: rgb(247, 247, 247);"&gt;The issue is exchange is sending the outgoing traffic via the outside interface of my firewall (213.42.201.46).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#777777"&gt;&lt;SPAN style="font-size: 14px; background-color: rgb(247, 247, 247);"&gt;HTH&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#777777"&gt;&lt;SPAN style="font-size: 14px; background-color: rgb(247, 247, 247);"&gt;Sandy&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2014 08:08:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/exchange-server-using-interface-ip-after-migrating-from-8-2-to-9/m-p/2450135#M934710</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2014-05-22T08:08:59Z</dc:date>
    </item>
    <item>
      <title>Dear SanthoshAs i mentioned,</title>
      <link>https://community.cisco.com/t5/network-security/exchange-server-using-interface-ip-after-migrating-from-8-2-to-9/m-p/2450136#M934717</link>
      <description>&lt;P&gt;Dear Santhosh&lt;/P&gt;&lt;P&gt;As i mentioned, i am not able to telnet to port 25 from outside. But my emails are working fine. I tried to figure out which ip is used by exchange using the MXpingtool and it says the outbound IP is 213.42.201.46 which is the outside interface.&lt;/P&gt;&lt;P&gt;In 9.x the access-lists are based on real IP so i am wondering &amp;nbsp;to permit DMZ IPs (172.16.2.11 &amp;amp; 21) in outside acl or it should be in DMZ acl??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Najeeb&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2014 08:15:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/exchange-server-using-interface-ip-after-migrating-from-8-2-to-9/m-p/2450136#M934717</guid>
      <dc:creator>najeeb_v</dc:creator>
      <dc:date>2014-05-22T08:15:03Z</dc:date>
    </item>
    <item>
      <title>Hi najeeb ,  You can verify</title>
      <link>https://community.cisco.com/t5/network-security/exchange-server-using-interface-ip-after-migrating-from-8-2-to-9/m-p/2450137#M934724</link>
      <description>&lt;P&gt;Hi najeeb ,&lt;/P&gt;&lt;P&gt;&amp;nbsp; You can verify it by packet-tracer command&lt;/P&gt;&lt;P&gt;packet-tracer input dmz tcp&amp;nbsp;&lt;SPAN style="color: rgb(119, 119, 119); font-family: 'comic sans ms', cursive; font-size: 14px;"&gt;172.16.2.11 25 8.8.8.8 25 xml , &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input dmz tcp&amp;nbsp;&lt;SPAN style="color: rgb(119, 119, 119); font-family: 'comic sans ms', cursive; font-size: 14px;"&gt;172.16.2.21 25 8.8.8.8 25 xml ,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-family: 'comic sans ms', cursive; font-size: 14px;"&gt;the output should show NAT IP being translated when its reaching to internet&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Kindly share me your show runn of your ASA box or share me following output .&lt;/P&gt;&lt;P&gt;1) show runn access-list&lt;/P&gt;&lt;P&gt;2) show runn access-group&lt;/P&gt;&lt;P&gt;3) show xlate&lt;/P&gt;&lt;P&gt;4) show run nat&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Sandy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2014 09:06:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/exchange-server-using-interface-ip-after-migrating-from-8-2-to-9/m-p/2450137#M934724</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2014-05-22T09:06:16Z</dc:date>
    </item>
    <item>
      <title>Dear Sandy, I was away from</title>
      <link>https://community.cisco.com/t5/network-security/exchange-server-using-interface-ip-after-migrating-from-8-2-to-9/m-p/2450138#M934726</link>
      <description>&lt;P&gt;Dear Sandy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was away from my desk, unfortunately i will not be able to get the information now as the client is already off and its a weekend here. I will provide the details to you as soon as i have the access to the device. Thanks for your support and appreciate your kind efforts.&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Najeeb&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2014 13:22:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/exchange-server-using-interface-ip-after-migrating-from-8-2-to-9/m-p/2450138#M934726</guid>
      <dc:creator>najeeb_v</dc:creator>
      <dc:date>2014-05-22T13:22:42Z</dc:date>
    </item>
    <item>
      <title>Dear Sandy, Kindly find the</title>
      <link>https://community.cisco.com/t5/network-security/exchange-server-using-interface-ip-after-migrating-from-8-2-to-9/m-p/2450139#M934727</link>
      <description>&lt;P&gt;Dear Sandy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly find the below below information as you requested.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2014 07:39:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/exchange-server-using-interface-ip-after-migrating-from-8-2-to-9/m-p/2450139#M934727</guid>
      <dc:creator>najeeb_v</dc:creator>
      <dc:date>2014-05-27T07:39:00Z</dc:date>
    </item>
  </channel>
</rss>

