Problem with cisco PIX 501 when using domain name to access port instead of IP
Posted on 2007-11-30
I have a Pix 501 firewall wich is currently allowing access to my mail server on ports 25 and 110 using NAT and Static Routes. The IP that "ties" the firewall with the server is the IP configured in the outside interface of the router (184.108.40.206). The internal server's ip is 10.0.1.1.
1. I can PING the 220.127.116.11 ip addres from any outside network with no problem, I get replies.
2. The IP is mapped through DNS to name mail.myserver.com. I can PING mail.myserver.com and get a reply from the IP with no problem.
2. I can telnet 18.104.22.168 on ports 25 and 100 and I can connect with no problem.
What does not work:
1. If I try to telnet de domain instead of the IP, for example telnet mail.myserver.com 25 or telnet mail.myserver.com 110 it takes a LOT of time to connect, sometimes it times out.
2. Because of this, mail clients return errors and do not download or send mail.
Question: Why would connecting through the domain name takes so long even if I can ping the domain name getting decent reply times, and I can connect to the ports with the ip address real quickly?
I tried removing the fixup for port 25, but same thing happens.
thanks a lot!!