Solved

How do I set my PIX to send SMTP from a different external IP?

Posted on 2009-05-03
4
376 Views
Last Modified: 2012-05-06
I have a block of external IPs on the outside of my PIX.  All traffic from the inside headed out goes through my default IP (lets say 1.1.1.1) but I want to send SMTP traffic through a different IP, 1.1.1.2.  How do I configure my PIX to send just SMTP traffic through that IP?
0
Comment
Question by:solidisquad
4 Comments
 
LVL 28

Accepted Solution

by:
batry_boy earned 500 total points
ID: 24291327
You have to use policy NAT...something like this:

access-list smtp-only permit tcp any any eq smtp
nat (inside) 10 access-list smtp-only
global (outside) 10 1.1.1.2

Just make sure that you use a different sequence number for your nat and global statements than you already have defined for your other outbound traffic and make sure they match (in this example, I used "10" to identify the nat and global statements to be used for the outbound SMTP traffic).

The statements above should work for ANY inside host sending outbound SMTP.  If you want to lock this down to a specific mail server on the inside, then you could put in the inside IP address of that mail server in the access list as shown below:

access-list smtp-only permit tcp host 192.168.1.20 any eq smtp
nat (inside) 10 access-list smtp-only
global (outside) 10 1.1.1.2

In the above example, only the SMTP traffic originating from inside host 192.168.1.20 will be translated to 1.1.1.2 once it passes through the firewall.  Any other outbound SMTP traffic will still use the global PAT address (1.1.1.1 from your post).
0
 

Author Comment

by:solidisquad
ID: 24296931
Awesome, thanks for your help!  I haven't done a Static NAT in that direction before, but that certainly makes sense.  I'll let you know once I've tested it.
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 36902112
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

I recently updated from an old PIX platform to the new ASA platform.  While upgrading, I was tremendously confused about how the VPN and AnyConnect licensing works.  It turns out that the ASA has 3 different VPN licensing schemes. "site-to-site" …
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

685 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question