?
Solved

Block outbound port 25 on Cisco Pix 501 to all devices except mail server

Posted on 2007-08-06
7
Medium Priority
?
6,218 Views
Last Modified: 2013-11-05
Hi Experts,

Our company has Cisco PIX 501.  My knowledge with Cisco is limited.  What we are trying to do is block outbound port 25 on our network except for our one mail server.  We want to do this to prevent PCs that may be infected with viruses from sending out spam.  This way we know the only PC on our network sending out mail is our mail server.  We would like all other outbound access to remain unaffected.  Is there any way to accomplish this?  On the linksys router we do a deny all smtp, then an allow for the mail server with a higher priority than the deny.  Is there any way to accomplish this?  Thanks for the help.
0
Comment
Question by:lukeca
7 Comments
 
LVL 29

Expert Comment

by:Jan Springer
ID: 19641752
This is very easily accomplished with ACLs on the PIX.

If I can presume that other than port 25 traffic is allowed:

access-list acl_outbound permit tcp any host ip.of.smtp.server eq 25
access-list acl_outbound deny tcp any any eq 25
access-list acl_outbound permit ip any any

access-group acl_outbound in interface inside
0
 
LVL 19

Accepted Solution

by:
nodisco earned 2000 total points
ID: 19642132
Actually - this will need to be done by source ip - so:

access-list acl_outbound permit tcp host [ip of smtp server] any eq 25
access-list acl_outbound deny tcp any any eq 25
access-list acl_outbound permit ip any any

access-group acl_outbound in interface inside

hope this helps

0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 19643407
nodisco has it right.

Cheers,
Rajesh
0
Veeam and MySQL: How to Perform Backup & Recovery

MySQL and the MariaDB variant are among the most used databases in Linux environments, and many critical applications support their data on them. Watch this recorded webinar to find out how Veeam Backup & Replication allows you to get consistent backups of MySQL databases.

 
LVL 29

Expert Comment

by:Jan Springer
ID: 19645450
I agree.  I read it as the mail server was outside the firewall.
0
 
LVL 7

Author Comment

by:lukeca
ID: 19648558
Thanks worked like a charm.
0
 

Expert Comment

by:deminois
ID: 20695081
Clean and to the point. Worked for me as well.
0
 

Expert Comment

by:Marvlus1
ID: 25034400
I Tried it too and it worked, excellent job.
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

On Feb. 28, Amazon’s Simple Storage Service (S3) went down after an employee issued the wrong command during a debugging exercise. Among those affected were big names like Netflix, Spotify and Expedia.
Considering cloud tradeoffs and determining the right mix for your organization.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses
Course of the Month14 days, 21 hours left to enroll

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question