Bypass Zone Based Firewall

Hello all,
We have recently replaced our premise router with an ASR.  We established a Zone Based Firewall since reflexive ACLs are no longer supported.  The problem we are having now is that SMTP traffic is SLOW.  External mail coming in with no attachments seems o.k. but when adding an attachment it can take hours.  In fact the last test took 13 hours to make it through.  At first we thought it was the Ironport but when talking with Cisco they said that it looks fine and normally the symptoms present themselves when there is packet inspection before the mail hits the Ironport.  Is there a way for SMTP to bypass the inspection policy but still be allowed through?  
laz01Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Matt VCommented:
In your config, is ip inspect SMTP enabled?

If it is, turn it off and let Ironmail do the inspection.
0
laz01Author Commented:
Negative.  It is not enabled.  
0
Jimmy Larsson, CISSP, CEHNetwork and Security consultantCommented:
In your policy map for traffic going between the appropriate zones, for SMTP-traffic do "pass" instead of "inspect.

If unsure what I mean, post your config here for clarification.

Best regards
Kvistofta
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
laz01Author Commented:
OK.  So that's what I ended up having to do.  I created an access-list for all smtp traffic, the appropriate class-maps and "pass" for the action.  
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Routers

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.