Improve company productivity with a Business Account.Sign Up

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 592
  • Last Modified:

ASA esmtp inspection

Hi

My mail server is behind a Cisco asa version 9.
I cannot send mail when esmtp inspection is enable on firewall using ports 465.
My question is how can I get e-mail working with esmtp inspection enabled as it now using having a firewall when security feature are disabled.
Please help someone
0
ciscosupp
Asked:
ciscosupp
  • 4
  • 3
  • 2
1 Solution
 
Henk van AchterbergSr. Technical ConsultantCommented:
In ASDM you are able to create  custom ESMTP rule "map".

Please look at the picture I created for you.
asa-esmtp.png
0
 
fgasimzadeCommented:
My personal advice - disable emstp inspection
0
 
Henk van AchterbergSr. Technical ConsultantCommented:
fgasimzade: I think the topic starter does know that disabling works but would like to use this security feature.

Disabling this feature is the "lazy" approach. When you want to enforce strict security ESMTP  inspection is a real good enforcement tool.

But with everything you enforce you will get extra support tickets when someone does not get through. That is why logging is very important!
0
Choose an Exciting Career in Cybersecurity

Help prevent cyber-threats and provide solutions to safeguard our global digital economy. Earn your MS in Cybersecurity. WGU’s MSCSIA degree program was designed in collaboration with national intelligence organizations and IT industry leaders.

 
ciscosuppAuthor Commented:
thanks fgasimzade

how can I do it via command line and what must I change
0
 
fgasimzadeCommented:
conf t
policy-map global_policy
 class inspection_default
no inspect esmtp
0
 
ciscosuppAuthor Commented:
mean thanks  henkva

how can I create a custom ESMTP rule via command line
0
 
ciscosuppAuthor Commented:
ok thanks for link will check it out
0
 
ciscosuppAuthor Commented:
policy-map type inspect esmtp tls-esmtp
parameters
allow-tls
inspect esmtp tls-esmtp


works perfect
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

The IT Degree for Career Advancement

Earn your B.S. in Network Operations and Security and become a network and IT security expert. This WGU degree program curriculum was designed with tech-savvy, self-motivated students in mind – allowing you to use your technical expertise, to address real-world business problems.

  • 4
  • 3
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now