cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
935
Views
0
Helpful
5
Replies

Exchange 2003 / Pix Firewall

sierputsch
Community Member

Hi everybody!

First of all i have to admit that i'm rather new to cisco networking products and well, this is my first pix 501 / exchange installation 😉

The scenario is as follows:

Inside Network: 16.37.16.0

Outside Network 83.42.12.16x (ISP: Gateway: 161)

Mail Server: 16.37.16.202 (on the Inside network)

I configured the Pix 501 via Terminal and NAT comunication seems ok.

I added following Statement to my PIX Access List:

access-list outside permit tcp any host 10.37.16.202 eq smtp

is there anything else i have to consider? should this configuration work if i put the exchange server live?

Many Thanks in advance!

Markus Sierputsch

5 Replies 5

paddyxdoyle
Level 11
Level 11

Hi,

You need to add a static command so mail server is visible from the outside ( you may have allready covered this )

You also need to apply your access list to your ouside interface

e.g.

access-group outside in interface outside

Other than this your default route should point to your ISP

route outside 0.0.0.0 0.0.0.0

I think this should be enough.

Rgds

Paddy

Do you have a static Public IP for the Mail server or do you use the same IP as the outside interface:

example with the same IP as the outside interface:

smtp server is: 10.37.16.202

ip address outside 83.42.12.16x 255.255.255.x

ip address inside 10.37.16.x 255.255.255.0

access-list outside permit tcp any interface outside eq smtp

access-group outside in interface outside

static (inside,outside) tcp interface smtp 10.37.16.202 smtp netmask 255.255.255.255 0 0

global (outside) 1 interface

nat (inside) 1 0.0.0.0 0.0.0.0 0 0

route outside 0.0.0.0 0.0.0.0 83.42.12.161

Example with a statics IP, differs from the outside interface:

## smtp server is: 10.37.16.202 Public = 83.42.12.y

ip address outside 83.42.12.16x 255.255.255.x

ip address inside 10.37.16.x 255.255.255.0

access-list outside permit tcp any host 83.42.12.16y eq smtp

access-group outside in interface outside

static (inside,outside) 83.42.12.y 10.37.16.202 netmask 255.255.255.255 0 0

global (outside) 1 interface

nat (inside) 1 0.0.0.0 0.0.0.0 0 0

route outside 0.0.0.0 0.0.0.0 83.42.12.161

sincerely

Patrick

Hi Patrick!

Thank you very much for your replies, ur help is much appreciated! 🙂

The IP Adress for the SMTP Server is the same as the public IP adress (static), at least its the ip address where our NIC DNS entry points at.

thank you very much!

best regards

Markus Sierputsch

brenteads
Community Member

Probably want to change the Fixup Protocol SMTP 25 to no fixup protocol smtp 25 as there are occasional problems with Exchange and ESMTP with the No Operation (NOP) command when exchanging mail. Sometimes you can get some odd traffic being sent and received and Exchange in particular won't "know" what to do with it and display the piece of email oddly.

The rest of the information added above looks textbook correct as well.

- Brent

Markus,

the pleasure is mine.

So you have to use the example that does the port redirection:

See also - Establishing Connectivity:

http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a0080172786.html

example:

smtp server is: 10.37.16.202

ip address outside 83.42.12.16x 255.255.255.x

ip address inside 10.37.16.x 255.255.255.0

access-list outside permit tcp any interface outside eq smtp

access-group outside in interface outside

static (inside,outside) tcp interface smtp 10.37.16.202 smtp netmask 255.255.255.255 0 0

global (outside) 1 interface

nat (inside) 1 0.0.0.0 0.0.0.0 0 0

route outside 0.0.0.0 0.0.0.0 83.42.12.161

Click on Rate this Post to help identify the most useful NetPro content.

sincerely

Patrick

Review Cisco Networking for a $25 gift card