cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1078
Views
0
Helpful
7
Replies

Accessing the SMTP from outside network through ASA 5510

mukalazisnr
Level 1
Level 1

hello good people,

I have an issue with my mail server(SME Server) which is behind a Cisco ASA 5500(firewall)  problem is that if one leaves my network they can receive but can not  send email via my SMTP also internal people can only send if they use  the IP address of the server rather than the domain (mail.xxxx.com) any pointers will be appreciated.

here is my layout

ISP - ASA 5510 - LAN (includes mailserver)

Kind regards

7 Replies 7

Hello George,

Are you using internal DNS, Could you also post the config of your ASA to have a look on the issue

regards

Harish

Thanks I have no internal DNS attached is the config

Kind Regards

Hello George,

If you have public DNS , in order to access the servers hosted inside using their fqdn, then you need  to have dns doctoring. but unfortunately, you are using port address translation ( not a one to one nat) which doesnt work well with dns doctoring..

I assume you can solve this issue with alias command as follows

alias (inside) 199.199.199.99    255.255.255.255

Also, for the other issue can you try to configure an SMTP inspection as follows

policy-map type inspect esmtp esmtp_map

parameters

allow-tls

policy-map global_policy

class inspection_default

inspect esmtp

Hope this helps

Regards

Harish

Thank you so much let me try that and get back to you

Still Cant Access

Stuart Gall
Level 1
Level 1

Following on from Harrison, with the latest asa software you can write a nat inside,inside rule to bounce traffic back to the internal server. What most people do though is have an internal dns that resolves to the rfc1918 ip of the server.

Sent from Cisco Technical Support iPad App

how do i do that?

Review Cisco Networking products for a $25 gift card