Solved

How do I set my PIX to send SMTP from a different external IP?

Posted on 2009-05-03
4
378 Views
Last Modified: 2012-05-06
I have a block of external IPs on the outside of my PIX.  All traffic from the inside headed out goes through my default IP (lets say 1.1.1.1) but I want to send SMTP traffic through a different IP, 1.1.1.2.  How do I configure my PIX to send just SMTP traffic through that IP?
0
Comment
Question by:solidisquad
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 28

Accepted Solution

by:
batry_boy earned 500 total points
ID: 24291327
You have to use policy NAT...something like this:

access-list smtp-only permit tcp any any eq smtp
nat (inside) 10 access-list smtp-only
global (outside) 10 1.1.1.2

Just make sure that you use a different sequence number for your nat and global statements than you already have defined for your other outbound traffic and make sure they match (in this example, I used "10" to identify the nat and global statements to be used for the outbound SMTP traffic).

The statements above should work for ANY inside host sending outbound SMTP.  If you want to lock this down to a specific mail server on the inside, then you could put in the inside IP address of that mail server in the access list as shown below:

access-list smtp-only permit tcp host 192.168.1.20 any eq smtp
nat (inside) 10 access-list smtp-only
global (outside) 10 1.1.1.2

In the above example, only the SMTP traffic originating from inside host 192.168.1.20 will be translated to 1.1.1.2 once it passes through the firewall.  Any other outbound SMTP traffic will still use the global PAT address (1.1.1.1 from your post).
0
 

Author Comment

by:solidisquad
ID: 24296931
Awesome, thanks for your help!  I haven't done a Static NAT in that direction before, but that certainly makes sense.  I'll let you know once I've tested it.
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 36902112
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
Let’s face it: one of the reasons your organization chose a SaaS solution (whether Microsoft Dynamics 365, Netsuite or SAP) is that it is subscription-based. The upkeep is done. Or so you think.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question