Solved

Setting Mail and Mail Gateway servers on PIX515e

Posted on 2004-09-09
9
362 Views
Last Modified: 2010-04-09
I have a PIX 515 Firewall. I am setting up an exchange server and need to send and receive e-mail thru a mail gateway. How do I allow traffic to and from the mail server thru the mail gateway. I also need to allow web-mail service. Thank you.

Setting Mail and Mail Gateway traffic on PIX515

I already did the following commands

pixfirewall#config term
pixfirewall(config)#static (inside,outside) tcp <public ip> 25 <mail_gateway ip> 25 netmask 255.255.255.255
pixfirewall(config)#access-list inbound_mail permit tcp any host <public ip> eq 25
pixfirewall(config)#access-group inbound_mail in interface outside
pixfirewall(config)#no fixup protocol smtp 25
pixfirewall(config)#clear xlate
pixfirewall(config)#exit
pixfirewall#
0
Comment
Question by:delsof
  • 4
  • 4
9 Comments
 
LVL 13

Expert Comment

by:td_miles
ID: 12023840
where is the mail gateway ?

how does the mail gateway communicate with your mail server (is it just SMTP) ?

The way I understand what you are saying, the mail gateway is going to send/receive all the email to/from the Internet. In this case, your configuration above seems fine. You need to configure EXCH to forward all emails  outbound to the gateway & you need to configure the gateway to send all emails inbound to EXCH (after it has checked them and verified that they are valid of course).

Are you going to use OWA for webmail ?
0
 
LVL 1

Author Comment

by:delsof
ID: 12027056
Thanks for replying.

The mail gateway is behind the firewall. The mail gateway and the mail server communicate via SMTP.

My current configuration is exactly as you mention it above. The "mail gateway is going to send/receive all the email to/from the Internet" and foward them to the EXCH server and viceversa for outbound emails. Thus, the above configuration is correct?

Yes, we are planning to use OWA from the EXCH server. Please advice.

DF
0
 
LVL 23

Expert Comment

by:Tim Holman
ID: 12027787
The above config looks fine.  Although you may need to reboot as well, as there is a known bug with some versions of PIX.
Also DISABLE mailguard.  It will upset Exchange.
0
 
LVL 13

Expert Comment

by:td_miles
ID: 12039812
If you want to enable OWA, then you need to setup a static NAT to port 80/443 for the EXCH server. I would advise ONLY using port 443 (ie. SSL) and then educating your users that they need to type "https://....."

To setup the NAT, it is same as you have already done for SMTP, just change the ports.

It's been a while since I looked into any potential security issues from OWA, so you may want to have a search/read about this prior to using OWA.
0
IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 
LVL 1

Author Comment

by:delsof
ID: 12045285
td_miles,

Should OWA settings looks like this?

pixfirewall#config term
pixfirewall(config)#static (inside,outside) tcp <webmail public ip> 443 <exch ip> 443 netmask 255.255.255.255
pixfirewall(config)#access-list inbound_mail permit tcp any host <webmail public ip> eq 443
pixfirewall(config)#access-group inbound_mail in interface outside
pixfirewall(config)#no fixup protocol https 443
pixfirewall(config)#clear xlate
pixfirewall(config)#exit
pixfirewall#

Thanks. DF
0
 
LVL 1

Author Comment

by:delsof
ID: 12045956
td_miles,

In addition, I am in the  process of converting security policies from a Checkpoint platform to Cisco Pix platform using the PDM. Any ideas.

DF
0
 
LVL 13

Expert Comment

by:td_miles
ID: 12051039
The lines in the config are correct to allow port 443 through to the exchange server. One line that you don't need is:

> pixfirewall(config)#no fixup protocol https 443

It is only for SMTP that you need to remove the fixup. Most other protocols it doesn't cause any issues.

----

> In addition, I am in the  process of converting security policies from a Checkpoint platform to Cisco Pix platform using the PDM. > Any ideas.

I assume that you are asking about automated solutions to convert from one to the other ? Not that I know of. Having a well documented security policy (in English with diagrams) means that it can then be implement on whatever platform you choose.
0
 
LVL 1

Author Comment

by:delsof
ID: 12054422
Thanks td_miles,

I don't have a lot of policies in my checkpoint server. I am looking to transport the policies manually by reading the policies on checkpoint and realize what field goes where in the PDM.
For example,
checkpoint has the following fields:
Source-Destination-If VIA-Service-Action-4 more
Any     -Any          -Any   -tcp http-accept-

Notice service got two set of information. How can I translate this to PDM?

Thx. DF
0
 
LVL 13

Accepted Solution

by:
td_miles earned 500 total points
ID: 12094958
Sorry about the delayed response. Yes, the policies should be translatable directly:

Checkpoint:
Source-Destination-If VIA-Service-Action-4 more
Any     -Any          -Any   -tcp http-accept-

PIX:
access-list 101 permit tcp any any eq 80

I don't normally use the PDM, so I can't say what the GUI looks like to configure, but if you are doing it from a command prompt, it is straight forward mapping as you can see from the above example.

The syntax for the access-list command is:
access-list id [line line-num] {deny | permit}{protocol | object-group protocol_obj_grp_id {source_addr source_mask} | object-group network_obj_grp_id [operator port [port] | interface if_name | object-group service_obj_grp_id] {destination_addr | remote_addr} {destination_mask | remote_mask} | object-group network_obj_grp_id [operator port [port] | object-group service_obj_grp_id]} [log [[disable | default] | [level]]] [interval secs]]

which looks very complicated, but in general you don't you need a lot of the options and it can be simplified to:

access-list id {deny | permit} source destination operator port
0

Featured Post

Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

Join & Write a Comment

Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now