Advertisement

04.18.2008 at 08:25AM PDT, ID: 23334462 | Points: 500
[x]
Attachment Details

pop3 behind a Cisco Pix

Asked by Claude_G in Cisco PIX Firewall, Broadband Internet

Tags: ,

I have a user who uses pop3 account from optonline.net but he is unable to send emails only send. I don't know what command to give. Please help! Thanks!

PIX Version 7.1(1)
!
hostname fnj254pix
domain-name shionogi-usa.com
enable password F1WT6/JtNLvh6.vs encrypted
names
!
interface Ethernet0
 speed 100
 duplex full
 nameif outside
 security-level 0
 ip address xx!
interface Ethernet1
 speed 100
 duplex full
 nameif inside
 security-level 100
 ip address xx
!
interface Ethernet2
 shutdown
 no nameif
 no security-level
 no ip address
!
passwd 2KFQnbNIdI.2KYOU encrypted
ftp mode passive
clock timezone EST -5
clock summer-time EDT recurring 2 Sun Mar 2:00 1 Sun Nov 2:00
dns server-group DefaultDNS
 domain-name shionogi-usa.com
same-security-traffic permit intra-interface
object-group service OWAmail tcp
 port-object eq https
 port-object eq smtp
object-group service Emule tcp
 port-object range 42983 42983
object-group service emule udp
 port-object range 6964 6964
object-group network JapanUsers
 network-object x0
 network-object x
object-group service ShionogiSMTP tcp
 port-object eq telnet
 port-object eq smtp
access-list outside_access_in extended permit icmp host xany
access-list outside_access_in extended permit tcp any host 71.4.148.131 object-group OWAmail
access-list outside_access_in extended permit ip x
access-list outside_access_in extended permit ip x
access-list outside_access_in extended permit tcp any host xeq 42983
access-list outside_access_in extended permit udp any host xeq 6964
access-list inside_nat0_outbound extended permit ip any x
access-list inside_nat0_outbound extended permit ip x.
access-list inside_nat0_outbound extended permit ip x
access-list SUIVPN06_splitTunnelAcl standard permit x
access-list outside_cryptomap_dyn_20 extended permit ip any x
access-list outside_cryptomap_90 extended permit ip x
access-list outside_cryptomap_70 extended permit ip x x
pager lines 24
logging timestamp
logging emblem
logging asdm informational
logging device-id hostname
logging host inside 10.90.11.1 format emblem
logging debug-trace
logging ftp-bufferwrap
logging ftp-server 10.90.11.1 \\f$\test gscinet\cgadmin ****
logging permit-hostdown
mtu outside 1500
mtu inside 1500
ip local pool VPNUsers x
icmp permit any outside
icmp permit any inside
asdm image flash:/asdm-511.bin
no asdm history enable
arp timeout 14400
global (outside) 10 xnetmask 255.255.255.224
nat (inside) 0 access-list inside_nat0_outbound
nat (inside) 10 0.0.0.0 0.0.0.0
static (inside,outside) xnetmask 255.255.255.255
static (inside,outside) x netmask 255.255.255.255
access-group outside_access_in in interface outside
route outside x1
route outside x
timeout xlate 0:30:00
timeout conn 0:45:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00
timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:10:00 absolute uauth 0:15:00 inactivity
aaa-server Fnj200dcIAS protocol radius
aaa-server Fnj200dcIAS host 10.90.0.200
 timeout 5
 key PixSui06
group-policy DfltGrpPolicy attributes
 banner none
 wins-server none
 dns-server none
 dhcp-network-scope none
 vpn-access-hours none
 vpn-simultaneous-logins 3
 vpn-idle-timeout 30
 vpn-session-timeout none
 vpn-filter none
 vpn-tunnel-protocol IPSec
 password-storage disable
 ip-comp disable
 re-xauth disable
 group-lock none
 pfs disable
 ipsec-udp disable
 ipsec-udp-port 10000
 split-tunnel-policy tunnelall
 split-tunnel-network-list none
 default-domain none
 split-dns none
 secure-unit-authentication disable
 user-authentication disable
 user-authentication-idle-timeout 30
 ip-phone-bypass disable
 leap-bypass disable
 nem disable
 backup-servers keep-client-config
 client-firewall none
 client-access-rule none
group-policy SUIVPN06 internal
group-policy SUIVPN06 attributes
 wins-server value x
 dns-server value x
 split-tunnel-policy tunnelspecified
 split-tunnel-network-list value SUIVPN06_splitTunnelAcl
 default-domain value shionogi-usa.com
url-server (inside) vendor websense host 10.90.0.230 timeout 10 protocol TCP version 4 connections 8
aaa authentication ssh console Fnj200dcIAS
aaa accounting ssh console Fnj200dcIAS
http server enable
http x inside
snmp-server host inside 10.90.11.1 community public version 2c
snmp-server location Edge
snmp-server contact cgrecea@shionogi-usa.com
snmp-server community public
snmp-server enable traps snmp authentication linkup linkdown coldstart
snmp-server enable traps ipsec start stop
snmp-server enable traps entity config-change fru-insert fru-remove
snmp-server enable traps remote-access session-threshold-exceeded
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
crypto ipsec transform-set cisco-netscreen esp-3des esp-md5-hmac
crypto dynamic-map outside_dyn_map 20 match address outside_cryptomap_dyn_20
crypto dynamic-map outside_dyn_map 20 set transform-set ESP-3DES-SHA
crypto map outside_map 70 match address outside_cryptomap_70
crypto map outside_map 70 set peer x
crypto map outside_map 70 set transform-set cisco-netscreen
crypto map outside_map 90 match address outside_cryptomap_90
crypto map outside_map 90 set peer x
crypto map outside_map 90 set transform-set cisco-netscreen
crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map
crypto map outside_map interface outside
isakmp identity address
isakmp enable outside
isakmp policy 10 authentication pre-share
isakmp policy 10 encryption 3des
isakmp policy 10 hash sha
isakmp policy 10 group 2
isakmp policy 10 lifetime 86400
isakmp policy 30 authentication pre-share
isakmp policy 30 encryption 3des
isakmp policy 30 hash md5
isakmp policy 30 group 2
isakmp policy 30 lifetime 86400
isakmp nat-traversal  20
tunnel-group SUIVPN06 type ipsec-ra
tunnel-group SUIVPN06 general-attributes
 address-pool VPNUsers
 authentication-server-group Fnj200dcIAS
 default-group-policy SUIVPN06
tunnel-group SUIVPN06 ipsec-attributes
 pre-shared-key *
tunnel-group xtype ipsec-l2l
tunnel-group xipsec-attributes
 pre-shared-key *
tunnel-group xtype ipsec-l2l
tunnel-group xipsec-attributes
 pre-shared-key *
telnet 10.90.0.0 255.255.240.0 inside
telnet timeout 5
ssh x255.255.255.255 outside
ssh 10.90.11.0 255.255.255.0 inside
ssh timeout 60
console timeout 0
dhcpd lease 3600
dhcpd ping_timeout 50
!
class-map inspection_default
 match default-inspection-traffic
!
!
policy-map global_policy
 class inspection_default
  inspect dns maximum-length 512
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect rsh
  inspect rtsp
  inspect sqlnet
  inspect skinny
  inspect sunrpc
  inspect xdmcp
  inspect sip
  inspect netbios
  inspect tftp
  inspect icmp
  inspect pptp
  inspect esmtp
policy-map asa_global_fw_policy
!
service-policy global_policy global
url-block url-mempool 10240
url-block url-size 4
tftp-server inside 10.90.11.1 /TFTP-Root
Cryptochecksum:42b0faad2dba1180d04d040c3ad622e6
: end
 what command in the cisco pix to turn on for him to able to access this.Start Free Trial
[+][-]04.18.2008 at 09:10AM PDT, ID: 21387106

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.18.2008 at 09:21AM PDT, ID: 21387222

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.18.2008 at 10:15AM PDT, ID: 21387752

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.18.2008 at 11:27AM PDT, ID: 21388397

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.22.2008 at 08:37AM PDT, ID: 21412163

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628