List Info

Thread: Incoming emails getting blocked behind PIX




Incoming emails getting blocked behind PIX
user name
2007-01-04 22:13:17

Try using this in the config:
 
 
no fixup protocol smtp 25
 
 
Roy Dumlao
 
 


From: Romulo Sousa [mailto:romulo_sousayahoo.com.br]
Sent: Sunday, December 31, 2006 12:11 PM
To: PIX_Firewallyahoogroups.com
Subject: Re: [PIX_Firewall] Incoming emails getting blocked behind PIX

Hi there,

I'm also having the same issue w/ the same application
(Exchange 2003).
Please, just let me know if the port 25 should be
declared as "permit" on the ACL.
Moreover, when I use public IP (200.x.x.x) it works
somehow. But when I use a private IP (192.x.x.x) it
doesn't. I can explain this problem of course with
more details if it needs.

Thanks a lot!

Romulo Sousa


--- Information Security Human < dudeinfosec%40gmail.com">dudeinfosecgmail.com>
wrote:

> Well a few things need to be checked,
&gt;
> 1) Did you ensure that the MX record for your domain
>; has been registered
> with whoever runs your county DNS pointing to the
> Public IP of your Exchange
&gt; server?

> 2) Did you ensure Port 25 incoming is open for
> incoming emails to the mail
> server Public IP address on the PIX firewall.
>
> If this is done, then PIX doesnot need any further
&gt; configuration
>
> InfoSec Dude
> Somewhere in the UAE
>
> On 12/17/06, anand_b_patil
> < anand_b_patil%40hotmail.com">anand_b_patilhotmail.com> wrote:
&gt; >
> > Hi,
> >
> > I'm trying to setup an Exchange Server 2003 behind
>; my PIX506E firewall.
> > I can se that all the outgoing emails can go but
> incoming emails are
> > not reaching the exchange server. I have created
&gt; the host and MX
> > records for the intended public IP. I have created
&gt; a simple NAT rule
> > using the PDM. I'm not sure if I need to open any
> ports like 25
> > specifically. When we send an email to the new
> intended ID, the error
> > message says the email delivery has been delayed
&gt; and shows the public
>; > IP of the Exchange server.
&gt; >
> > If anyone has any idea, please help.
>; >
> > - Thanks.
&gt; >
> >
> >
>
>
>
> --
> Information Security Dude,
>; CISSP, CISA, CWNA, ISMS LA
> Somewhere in UAE.
>

__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com

__._,_.___
.

__,_._,___
[1]

about | contact  Other archives ( Real Estate discussion Medical topics )