Solved

How do I set my PIX to send SMTP from a different external IP?

Posted on 2009-05-03
4
371 Views
Last Modified: 2012-05-06
I have a block of external IPs on the outside of my PIX.  All traffic from the inside headed out goes through my default IP (lets say 1.1.1.1) but I want to send SMTP traffic through a different IP, 1.1.1.2.  How do I configure my PIX to send just SMTP traffic through that IP?
0
Comment
Question by:solidisquad
4 Comments
 
LVL 28

Accepted Solution

by:
batry_boy earned 500 total points
Comment Utility
You have to use policy NAT...something like this:

access-list smtp-only permit tcp any any eq smtp
nat (inside) 10 access-list smtp-only
global (outside) 10 1.1.1.2

Just make sure that you use a different sequence number for your nat and global statements than you already have defined for your other outbound traffic and make sure they match (in this example, I used "10" to identify the nat and global statements to be used for the outbound SMTP traffic).

The statements above should work for ANY inside host sending outbound SMTP.  If you want to lock this down to a specific mail server on the inside, then you could put in the inside IP address of that mail server in the access list as shown below:

access-list smtp-only permit tcp host 192.168.1.20 any eq smtp
nat (inside) 10 access-list smtp-only
global (outside) 10 1.1.1.2

In the above example, only the SMTP traffic originating from inside host 192.168.1.20 will be translated to 1.1.1.2 once it passes through the firewall.  Any other outbound SMTP traffic will still use the global PAT address (1.1.1.1 from your post).
0
 

Author Comment

by:solidisquad
Comment Utility
Awesome, thanks for your help!  I haven't done a Static NAT in that direction before, but that certainly makes sense.  I'll let you know once I've tested it.
0
 
LVL 35

Expert Comment

by:Ernie Beek
Comment Utility
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

There are many useful and sometimes not well documented or forgotten IOS or ASA/PIX commands. See IPE article here , there was also one on PacketU and on Cisco Tips & Tricks. Below are my favorites. I give also a few most often used for Cisco IPS an…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now