Link to home
Start Free TrialLog in
Avatar of jtennyson
jtennysonFlag for United States of America

asked on

Problem with firewall accepting mail

We recently moved to new office.  I had a consultant set up the firewall.  He was supposed to configure it exactly as the old one.  He didn't and now he can not be reached.
Our MX record points to a SPAM filtering company.  They then send our mail to us.  For the first day they could not send us any mail.  Then I finally got the consultant to put in a change to fix it.  This morning I received this message from the SPAM company.

Still having issues delivering mail to your server consistently.  I currently have 85 messages in queue for your domain.  They have been slowly climbing.  

I see most mail is going through ok but some seems to be getting an error from your server/firewall:
 
2011-03-23T16:34:40.351358-04:00 dpout01 postfix/smtp[417]: 4E9E41C781FB: to=<drocha@rgrayclamps.com>, relay=mail.rgrayclamps.com[12.204.121.3]:25, delay=1013, delays=680/0/0.1/333, dsn=4.4.2, status=deferred (lost connection with mail.rgrayclamps.com[12.204.121.3] while sending end of data -- message may be sent more than once)
 
If you have ‘smtp fixup’ set on your firewall, you will want to disable that, it definitely could cause these types of issues.

I do not have smtp fixup set on the firewall.
Avatar of Ernie Beek
Ernie Beek
Flag of Netherlands image

Hi there :)

Could be a number of things so let's see. Looking at the config from your previous question I see no smtp fixup indeed. By the way, it is called 'inspect' in the ASA.
You do have an inspect esmtp which might be the issue.

On the other hand I see that you are only allowing smtp traffic in from a number of ip ranges. Are you sure that all the ip addresses from where your SPAM filtering company could send you mail are covered?
Avatar of jtennyson

ASKER

I am going to check with them right now.
The company is in California so I am sure they will not be in for a couple of hours.
Always nice, different timezones :)

Allright, let's just wait then for now and let me know when they are in.
They did get back to me and they said those are the correct addresses.

access-list internet extended permit tcp 64.19.188.16 255.255.255.240 any eq smtp
access-list internet extended permit tcp 206.188.13.128 255.255.255.240 any eq smtp
access-list internet extended permit tcp 4.78.136.16 255.255.255.240 any eq smtp
ASKER CERTIFIED SOLUTION
Avatar of Ernie Beek
Ernie Beek
Flag of Netherlands image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Thanks again.  I made the changes and will let you know what happens.
I'll be here :)
Should I reboot the firewall?
Avatar of shubhanshu_jaiswal
shubhanshu_jaiswal

disabling ESMTP Inspection should solve the issue...
Not really. Those changes should be effective immediatly.
Once again you are the best.
Thx, only I'm afraid you awarded the wrong one :-(
I'm so sorry.  I would double the points for you if I could.  I hope your reading on Monday I will need more help.
Never mind, I was convinced it wasn't your intention.
See you on monday :)