Solved

Cisco ASA 5510 and portforwarding for SMTP

Posted on 2010-09-09
10
821 Views
Last Modified: 2012-05-10
Good Morning,
I recently experienced an issue where my Cisco ASA 5510 just magically stopped forwarding SMTP traffic from outside my organization.  I have never used a ASA before.  My OWA access works and internal mail still flows.  IT is when someone outside the organization attempts to email someone here at my company, the email either does not make it and they get an errror message or it is very extremely slow in getting here.

I have attached a copy of the running config from my ASA.
running-config
0
Comment
Question by:dillingerm
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
  • +2
10 Comments
 
LVL 4

Expert Comment

by:mpickreign
ID: 33637186
The ASA config looks good, and the fact that you say some mail comes in, albeit slowly, indicates the issue is elsewhere. If the ASA was blocking mail, it would never come through.

What kind of error messages are the remote senders getting?  
0
 

Author Comment

by:dillingerm
ID: 33637229
This is what I get when I try to send my self an email from my hotmail:
This is an automatically generated Delivery Status Notification.
 
Delivery to the following recipients failed.
 
  <email address>

I also am not able to telnet to my email server from outside either.  I had posted up in the exchange blogs and they advised me to come look here.  I think it would almost have to do with the firewall seeing how I  am not able to telnet into port 25 from outside.  My outisde ip for email is 64.187.68.37-this is where i am unable to telnet to
0
 
LVL 4

Expert Comment

by:mpickreign
ID: 33637401
Actually it looks like your external IP for mail is 64.187.68.34  and I am able to telnet into it on 25.
0
Building an interactive eFuture classroom

Watch and learn how ATEN provided a total control system solution including seamless switching matrix switch, HDBaseT extenders, PDU, lighting control to build an interactive eFuture classroom.

 

Author Comment

by:dillingerm
ID: 33639782
That is my old mail server.  My previous colleague replaced it with a new box before his departure.  I removed that mx record and then things started going funky after that
0
 
LVL 3

Expert Comment

by:Mystique_87
ID: 33640180
--which is the mail server you are currently using?
Is it 10.10.4.7 or 10.10.4.12
--tell us the inside and the outside ip address of the mail server you are currently using
0
 

Author Comment

by:dillingerm
ID: 33640208
10.10.4.12 is Inside IP of Email Server
64.187.68.37 is outside IP of Email server.
0
 
LVL 13

Accepted Solution

by:
3nerds earned 500 total points
ID: 33640548
You access list is wrong, this line:

access-list OUT->IN extended permit tcp any eq smtp host SHSMXC001_Inside eq smtp

should be

access-list OUT->IN extended permit tcp any eq smtp host SHSMXC001 eq smtp

As a side note because your using a PAT for you outside to inside when you send mail out it will still go out 64.187.68.34 which is a good thing because you do not have a reverse record set for .37 and this would cause your mail to end up in smap folders.

Regards,

3nerds
0
 
LVL 3

Expert Comment

by:Mystique_87
ID: 33640804
So the mail server 10.10.4.12 gets natted to 64.187.68.37.
So anybody who wants to access the mail server from outside has to access using the public ip 64.187.68.37.

so add another entry to thr access-list OUT->IN:
access-list OUT->IN extended permit tcp any host SHSMXC001 eq smtp

also add another static entry:

static(inside,outside) SHSMXC001 eq 25 SHSMXC001_Inside eq 25
0
 
LVL 69

Expert Comment

by:Qlemo
ID: 34391603
This question has been classified as abandoned and is being closed as part of the Cleanup Program.  See my comment at the end of the question for more details.
0

Featured Post

Surfing Is Meant To Be Done Outdoors

Featuring its rugged IP67 compliant exterior and delivering broad, fast, and reliable Wi-Fi coverage, the AP322 is the ideal solution for the outdoors. Manage this AP with either a Firebox as a gateway controller, or with the Wi-Fi Cloud for an expanded set of management features

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Rdp session freeze periodically in FORTIGATE ssl vpn 2 77
Grant drive/folder change permissions to VPN user 6 29
Clientless VPN Access 23 40
auto connect vpn 17 53
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question