Solved

Block SMTP on ASA 5500

Posted on 2011-02-15
6
1,485 Views
Last Modified: 2012-05-11
Hello we would like it so that only the exchange server is allowed to send email out from the network. We have had some issues where users have taken their virus infected home computer to the office. How can we setup the ASA so that it only allows the exchange server to send email on port 25?

This is my acl:

access-list outside_access_in extended permit tcp any host 213.145.177.74 eq smtp
access-list outside_access_in extended permit tcp any host 213.145.177.74 eq https
access-list outside_access_in extended permit tcp host 10.10.1.1 any eq smtp
access-list outside_access_in extended permit tcp host 10.10.1.202 any eq smtp
access-list outside_access_in extended deny tcp any any eq smtp

0
Comment
Question by:daxa78
  • 4
  • 2
6 Comments
 
LVL 35

Accepted Solution

by:
Ernie Beek earned 500 total points
ID: 34896355
You have to create an accesslist on the inside interface, something like:

access-list inside_access_out extended permit tcp host x.x.x.x any eq smtp (x.x.x.x = exchange server)
access-list inside_access_out extended deny tcp any any eq smtp
access-list inside_access_out extended permit ip any any


That should do the trick.
0
 
LVL 1

Author Comment

by:daxa78
ID: 34896498
So i should just delete those other acl?

Thx
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 34896525
Well, no. Those are the incoming rules. I think you still want your exchange server to be reachable don't you? You might to have a look to see if anything can be removed (i see three times incoming smtp).
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 1

Author Comment

by:daxa78
ID: 34896685
Did not work this is what my acl looks like now.

All host on the network can still connect to smtp servers on the outside.

access-list inside_access_out extended permit tcp host 10.10.1.1 any eq smtp
access-list inside_access_out extended permit tcp host 10.10.1.202 any eq smtp
access-list inside_access_out extended deny tcp any any eq smtp
access-list inside_access_out extended permit ip any any
0
 
LVL 35

Assisted Solution

by:Ernie Beek
Ernie Beek earned 500 total points
ID: 34896774
Eh, did you also issue: acces-group inside_access_out in interface inside ?

Assuming the name of your inside interface is 'inside'.
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 34897608
Thanks for the points.

Regarding your outside accesslist, you might want to remove:


access-list outside_access_in extended permit tcp host 10.10.1.1 any eq smtp
access-list outside_access_in extended permit tcp host 10.10.1.202 any eq smtp
access-list outside_access_in extended deny tcp any any eq smtp


There's no need for those and there's allways an implicit 'deny all' at the end of an access list.
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
Overview The Cisco PIX 501, PIX 506e, ASA 5505 and ASA 5510 (most if not all of this information will be relevant to the PIX 515e but I do not have a working configuration handy to verify the validity) are primarily used within small to medium busi…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now