08-02-2016 07:45 PM
Hello Experts,
I want to know that if I deploy the ESA into my network without public IP address with a config on the ASA as if is there any traffic for port 25 then forwards it to the ESA then to the Exchange.
I have published my firewall's public IP address in the MX record.
In this scenario, will there be any issue for the ESA to determine sender's reputation while receiving an email?
And if the ESA is not able to determine sender's reputation then what is the best way to deploy the ESA without using a public IP address.
Solved! Go to Solution.
08-03-2016 07:17 AM
I would expect that 99% of ESA-installations are using a private IP on the public listener with static NAT on the firewall in front of the ESA. There is nothing wrong on this. Just think about what get's translated here. It's the destination IP of the request that comes from the internet and the ESA still sees the IP of the sender. Only your internal Mailserver doesn't see the original sender-IP. But that typically doesn't matter as the SPAM-check is already done when the mail hits the internal server.
08-02-2016 10:38 PM
Hello Kachavda,
On the ESA it does not require a public IP interface.
But when connection comes from internet -> ASA -> ESA -> Exchange
When ASA -> ESA, is the ASA going to mask the original source IP with it's own?
If this is the case, it will break SBRS filtering and the recommended settings if this is the case is to run an incoming relay setup so we can look for the original source IP within email headers.
Regards,
matthew
08-03-2016 07:14 PM
Hi Mathew,
Thank you for your reply. ASA is not going to mask source IP with its own.
08-03-2016 07:17 AM
I would expect that 99% of ESA-installations are using a private IP on the public listener with static NAT on the firewall in front of the ESA. There is nothing wrong on this. Just think about what get's translated here. It's the destination IP of the request that comes from the internet and the ESA still sees the IP of the sender. Only your internal Mailserver doesn't see the original sender-IP. But that typically doesn't matter as the SPAM-check is already done when the mail hits the internal server.
08-03-2016 07:18 PM
Thanks Karsten for helping.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide