06-24-2011 01:06 PM - edited 03-04-2019 12:48 PM
I have a 2600 router on the edge of my network...connected to a DSL line...dnyamic IP handeled by DYNDNS service.
I am running a Windows 2003 server with Exchange 2003 on it...
I have the following lines in my config file :
ip nat inside source static tcp 192.168.0.10 25 interface Dialer0 25
access-list 104 permit tcp any any eq smtp (104 is the Dialer0 outside interface)
am I missing any access-list entries?
ATTACHED IS MY CONFIG FILE
06-24-2011 01:48 PM
Hi,
Your configuration looks good to me. It's for incomming SMTP traffic from outside to inside. However,I didn't see you inspect SMTP for outgoing mails from inside to outside.
HTH,
Toshi
06-24-2011 02:30 PM
so can you tell me what i may be missing....what lines do I need to add
06-25-2011 03:00 AM
Hi David,
The conf looks ok. ACLs configuration purely depends upon your business requirements.
But, couple of comments...
1. Try to be as specific as possible in ACLs (I meant instead of allowing any any eq 25, pls do it for specific mail server ip)
2. I have seen a separate interface for DMZ Zone where we generally put the servers facing outside. You may move your e-mail server facing outside to DMZ interface.
Regards...
-Ashok.
06-25-2011 08:57 AM
Unfortunatley I do not have a DMZ...my server is on my LAN.
I know a DMZ would be the normal way to set it up..but this way should still work.
Am I missing an ACL for SMTP inside to outside that I need to configur...if so can you give me some help with that.
I am still learning cisco stuff.
thankls
06-25-2011 09:31 AM
Hi,
You just add "ip inspect name SDM_LOW smtp" on it.
HTH,
Toshi
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide