trouble after upgrading Pix firewall software
Posted on 2006-07-17
I upgraded our Cisco Pix 506e firewall software from version 6.3.1 to 6.3.5 over the weekend.
After the upgrade, all of our non-Microsoft email clients were unable to send or receive email. After changing their POP and SMTP settings from MAIL.OUTDOMAINNAME.COM to x.x.x.x (our Exchange server's internal IP address), we were able to get and send mail.
However, now we cannot get to our web based outlook email (at least internally, i haven't checked it outside the LAN yet).
I checked the Exchange server, and everything looks OK.
So then I checked the Pix software, went to the Pix Device Manager 3.0, Options/ Show Commands Ignored by PDM on Firewall. & found this:
fixup protocol dns maximum-length 512
fixup protocol tftp 69
access-list 100 permit udp any host xx.xx.xx.xx eq www
access-list acl_outside permit tcp any host x.x.x.x eq https
timeout sip-disconnect 0:02:00 sip-invite 0:03:00
aaa-server TACACS+ max-failed-attempts 3
aaa-server TACACS+ deadtime 10
aaa-server RADIUS max-failed-attempts 3
aaa-server RADIUS deadtime 10
(where xx.xx.xx.xx = our MX record IP address
x.x.x.x = the internal IP address of our Exchange server)
Any help will be greatly appreciated!