Problem with firewall accepting mail

We recently moved to new office.  I had a consultant set up the firewall.  He was supposed to configure it exactly as the old one.  He didn't and now he can not be reached.
Our MX record points to a SPAM filtering company.  They then send our mail to us.  For the first day they could not send us any mail.  Then I finally got the consultant to put in a change to fix it.  This morning I received this message from the SPAM company.

Still having issues delivering mail to your server consistently.  I currently have 85 messages in queue for your domain.  They have been slowly climbing.  

I see most mail is going through ok but some seems to be getting an error from your server/firewall:
 
2011-03-23T16:34:40.351358-04:00 dpout01 postfix/smtp[417]: 4E9E41C781FB: to=<drocha@rgrayclamps.com>, relay=mail.rgrayclamps.com[12.204.121.3]:25, delay=1013, delays=680/0/0.1/333, dsn=4.4.2, status=deferred (lost connection with mail.rgrayclamps.com[12.204.121.3] while sending end of data -- message may be sent more than once)
 
If you have ‘smtp fixup’ set on your firewall, you will want to disable that, it definitely could cause these types of issues.

I do not have smtp fixup set on the firewall.
jtennysonAsked:
Who is Participating?
 
Ernie BeekConnect With a Mentor ExpertCommented:
Ok, in that case let's remove the line 'inspect esmtp'. That's used for smtp and esmtp. See if that helps.

To remove it:

conf t
policy-map global_policy
class inspection_default
no inspect esmtp
exit


Oh, it might be an idea to change those lines to:

access-list internet extended permit tcp 64.19.188.16 255.255.255.240 host 12.204.121.3 eq smtp
access-list internet extended permit tcp 206.188.13.128 255.255.255.240 host 12.204.121.3 eq smtp
access-list internet extended permit tcp 4.78.136.16 255.255.255.240 host 12.204.121.3 eq smtp

Assuming 12.204.121.3 is the public address of the mailserver and the only host where you would want to allow smtp connections to.
0
 
Ernie BeekExpertCommented:
Hi there :)

Could be a number of things so let's see. Looking at the config from your previous question I see no smtp fixup indeed. By the way, it is called 'inspect' in the ASA.
You do have an inspect esmtp which might be the issue.

On the other hand I see that you are only allowing smtp traffic in from a number of ip ranges. Are you sure that all the ip addresses from where your SPAM filtering company could send you mail are covered?
0
 
jtennysonAuthor Commented:
I am going to check with them right now.
0
What Kind of Coding Program is Right for You?

There are many ways to learn to code these days. From coding bootcamps like Flatiron School to online courses to totally free beginner resources. The best way to learn to code depends on many factors, but the most important one is you. See what course is best for you.

 
jtennysonAuthor Commented:
The company is in California so I am sure they will not be in for a couple of hours.
0
 
Ernie BeekExpertCommented:
Always nice, different timezones :)

Allright, let's just wait then for now and let me know when they are in.
0
 
jtennysonAuthor Commented:
They did get back to me and they said those are the correct addresses.

access-list internet extended permit tcp 64.19.188.16 255.255.255.240 any eq smtp
access-list internet extended permit tcp 206.188.13.128 255.255.255.240 any eq smtp
access-list internet extended permit tcp 4.78.136.16 255.255.255.240 any eq smtp
0
 
jtennysonAuthor Commented:
Thanks again.  I made the changes and will let you know what happens.
0
 
Ernie BeekExpertCommented:
I'll be here :)
0
 
jtennysonAuthor Commented:
Should I reboot the firewall?
0
 
shubhanshu_jaiswalCommented:
disabling ESMTP Inspection should solve the issue...
0
 
Ernie BeekExpertCommented:
Not really. Those changes should be effective immediatly.
0
 
jtennysonAuthor Commented:
Once again you are the best.
0
 
Ernie BeekExpertCommented:
Thx, only I'm afraid you awarded the wrong one :-(
0
 
jtennysonAuthor Commented:
I'm so sorry.  I would double the points for you if I could.  I hope your reading on Monday I will need more help.
0
 
Ernie BeekExpertCommented:
Never mind, I was convinced it wasn't your intention.
See you on monday :)
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.