10-10-2005 02:29 AM - edited 02-21-2020 02:02 PM
We are using a PIX501 with a default configuration, with a few VPN accounts setup as well.
When users connect through VPN, using the Cisco VPN client with the AES-256 transform set (if that makes a difference), IMAP works (port 143), secure IMAP works (port 993), SSH works (port 22) but SMTP (port 25) and POP3 (110) do not work.
All of the above services are running on the same machine, which happily accepts connections from anywhere regardless of IP address.
Also note that when we are connected through the VPN, we get an IP address in the same subnet as the machine we are trying to connect to. This has been confirmed by connecting successfully to port 80, and then looking at the apache logs.
We have tried disabling the default smtp fixup line in the config, but the problems still remain.
Any suggestions are very much appreciated!
Thanks,
Richard.
10-10-2005 05:06 AM
just wondering if all these protocols, including imap, secure imap, ssh, smtp, and pop3 are only avaliable via vpn. or few of them are available from the internet directly with static nat/pat configured on the pix.
maybe post the config.
10-11-2005 12:37 AM
they are only available via vpn, and this is the way they should be.
10-11-2005 04:22 AM
the issue maybe either related to the nat/pat or outbound acl.
please post the config.
10-11-2005 05:06 AM
i'd rather not post the entire config from our company firewall if that's ok... are there any particular settings you need to see?
10-11-2005 04:26 PM
it should be fine if you masked all the public ip info. if it's not feasible, please post the part with nat/pat/global/static and acls.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide