cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
761
Views
5
Helpful
8
Replies

Cisco ESA 300V doc file block

currently we deploy ESA 300V for one of our customer. there are some issue with *.doc files. while we send the attachment with .doc file it will be block. I remove all content filters from both incoming and outgoing mail policies. but the issue remain same.  Please advice. 

version : 11.0.0.1-264

8 REPLIES 8
Cisco Employee

Re: Cisco ESA 300V doc file block

Can you review the message tracking to see how the attachment was blocked?

 

It should display how if at all the attachment was blocked by the ESA.

 

Regards,

Libin Varghese

Re: Cisco ESA 300V doc file block

Hi Libin,

attached hear is the message track of an attachement email.  Seems there is a bit latenecy as well.

trace.JPG

Cisco Employee

Re: Cisco ESA 300V doc file block

This message means that the message injection was prematurely terminated. This will show up in the mail logs on the Email Security Appliance as  "ICID lost." This is almost always indicative of an intermediate firewall, content filter or other device terminating the SMTP conversation.

 

https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/118295-technote-esa-00.html

 

Regards,

Libin Varghese

Re: Cisco ESA 300V doc file block

Hi Libin,

Can you please let us know the perticular ports to to check from firewall.

 

Thanks

Cisco Employee

Re: Cisco ESA 300V doc file block

SMTP uses port 25 alone, however there should not be any SMTP inspection features enabled on the firewall which modifies the traffic in any way.

 

- Libin V

Re: Cisco ESA 300V doc file block

Hi Libin,

attached hear is the message track of an attachement email.  Seems there is a bit latenecy as well.

trace.JPG

Re: Cisco ESA 300V doc file block

Hi Libin,

attached hear is the message track of an attachement email.  Seems there is a bit latenecy as well.

trace.JPG

Highlighted

Re: Cisco ESA 300V doc file block

Hi Libin,

attached hear is the message track of an attachement email.  Seems there is a bit latenecy as well.

 

trace.JPG

Everyone's tags (3)