05-31-2013 02:22 AM - edited 03-11-2019 06:51 PM
Hello,
PIX525 OS 6.3
I´m configuring a service of mail relay in my network, but i cant send mail's outside my network.
In telnet to my relay server outside and i recieve the 220*********************************** message.
I already have the "no fixup protocol smtp 25" command on pix but the result of telnet is still the same.
on command line
PIX525# show fixup protocol smtp
no fixup protocol smtp 25
what could be the problem?
Thanks in advance
Paulo
05-31-2013 02:32 AM
Hi,
Doesnt the code 220 imply that you get in return to the telnet that the SMTP server responded and port TCP/25 is open?
- Jouni
05-31-2013 02:39 AM
Hi,
it's my first time with a pix firewall but my question is related to this lines i have read
"
As of Version 5.1 and higher, the fixup protocol smtp command changes the characters in the server SMTP banner to asterisks except for the "2", "0", "0" characters. Carriage return (CR) and linefeed (LF) characters are ignored. PIX Firewall Version 4.4 converts all characters in the SMTP banner to asterisks. "
in :
http://www.cisco.com/en/US/docs/security/pix/pix63/configuration/guide/fixup.html#wp1103507
can you confirm that?
Thanks
05-31-2013 02:49 AM
Hi,
We dont have any devices running such an old software level.
Our firewalls with ESMTP inspection dont return a banner with all "*" if that is your question.
- Jouni
05-31-2013 03:07 AM
Ok, let me try to explain,
My PIX SO it's 6.3
Wend i try to send a mail outside with mail relay with postfix i get this log from mail server
" < outbound-relay-in.ptprime.pt[62.28.164.245]:25: 220 ***************************************
postfix/smtp[6266]: name_mask: disable_esmtp
correio postfix/smtp[6266]: name_mask: delay_dotcrlf
correio postfix/smtp[6266]: B648127C2466: enabling PIX workarounds: disable_esmtp delay_dotcrlf for outbound-relay-in.ptprime.pt[62.28.164.245]:25
......."
For what i have read in other posts if i disable smtp inspection i will not have this problem anymore.
The relay server should answer with the smtp banner with no "***"
Is this right?
Thanks,
Paulo
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide