We help IT Professionals succeed at work.

Cisco ASA 5505 and MS Exchange Server

Mike
Mike asked
on
1,390 Views
Last Modified: 2013-01-04
Since we lost the password for our WAN Checkpoint FW, I am replacing it with an ASA5505. To start with, I keeping it wide open “permit ip any any” as it is a secured private MPLS between our sits only. Everything is working fine, can ping systems between sites and RDP computers etc… except that our MS Exchange Server not working or communicating with the primary exchange server in other site to send or receive any emails… But I can ping and RDP both servers from both end.

Since it is wide open “permit ip any any”; anything else I need to permit/configure in ASA 5505 for the MS Exchange traffic to pass through?
Comment
Watch Question

Senior Network Administrator
Commented:
This one is on us!
(Get your first solution completely free - no credit card required)
UNLOCK SOLUTION
MikeAnalyst

Author

Commented:
Since ASA using "inspect" I tried the following, still not working..

conf t
policy-map global_policy
class inspection_default
no inspect esmtp

-----------------------------------



access-list FromOutside extended permit ip any any

access-list FromOutside extended permit esp any any

access-list FromOutside extended permit udp any eq isakmp any

access-list FromOutside extended permit udp any eq 4500 any

access-list FromInside extended permit ip any any


************************

global (outside) 1 interface

nat (inside) 0 access-list nonat_acl

access-group FromInside in interface inside

access-group FromOutside in interface outside

***************************

class-map inspection_default

 match default-inspection-traffic

!

!

policy-map type inspect dns preset_dns_map

 parameters

  message-length maximum 512

policy-map global_policy

 class inspection_default

  inspect dns preset_dns_map

  inspect ftp

  inspect h323 h225

  inspect h323 ras

  inspect netbios

  inspect rsh

  inspect rtsp
             
  inspect skinny

  inspect sqlnet

  inspect sunrpc

  inspect tftp

  inspect sip

  inspect xdmcp

!

service-policy global_policy global
MikeAnalyst

Author

Commented:
Thanks gdewrell

Acutally it has to do with fixup/inspect. I just need to power off and power on after the changes.  It is working now.
MikeAnalyst

Author

Commented:
conf t
policy-map global_policy
class inspection_default
no inspect esmtp
wr

power off and on worked.  Thanks gdewrell.

http://support.microsoft.com/kb/161931
http://support.microsoft.com/kb/176466

Gain unlimited access to on-demand training courses with an Experts Exchange subscription.

Get Access
Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Empower Your Career
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE

Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

  • Troubleshooting
  • Research
  • Professional Opinions
Unlock the solution to this question.
Join our community and discover your potential

Experts Exchange is the only place where you can interact directly with leading experts in the technology field. Become a member today and access the collective knowledge of thousands of technology experts.

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.