Inbound SMTP Traffic through PIX515
Posted on 2008-10-06
I am having a very odd intermittent problem with my PIX515 firewall. The architecture is as follows.
I have a fullt T1 connection that's protected by a PIX 515 firewall. This firewall has 3 interfaces (Inside, Outside, DMZ). On the inside interface the firewall is plugged into a Cisco CAT4507 switch. Also on that switch is a Sonicwall Email Security 200 appliance for SPAM filtering. The sonicwall is on the "internal" corporate network (no separate VLANs or other Firewalls involved). The Sonicwall scans the email, and then forwards on to a corporate exchange server again, on the same internal network.
Almost on a daily basis, but not at definable intervals, we are unable to recieve inbound SMTP traffic through the firewall. A telnet from the outside to the NAT mail interface on port 25 fails (when mail is flowing the SMTP Telnet is normal, no fixup/mailguard is enabled). HOWEVER, when mail is not flowing, a Telnet to port 25 of the Email Security Appliance INSIDE the firewall is fine, as is all outbound SMTP traffic, and the http/https management utilites on the device. Inbound is the only thing affected. A hard reboot of the Email Security Device usually gets things up and running again.
I'm getting a lot of finger pointing back and forth but haven't had much luck...