Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Can the PIX515E running 7.0 affect SMTP behavior? 1

Status
Not open for further replies.

skhoury

IS-IT--Management
Nov 28, 2003
386
US
Hello all,

I've got a very unusual problem at hand here.

Here is the scenario, any help is much appreciated!

We have a Cisco PIX 515E running 7.0, and an internal SMTP mail server.

In the configuration, I have a static map from an external IP to the internal IP of the mail server.

static (inside,outside) ex.te.rn.al 192.168.1.32 netmask 255.255.255.255

Then, I have an access-list defined to all SMTP traffic inbound to that particual external IP.

access-list from_outside_coming_in extended permit tcp any host ex.te.rn.al eq smtp

Now, this is the wierd part. We have an internal Exchange server, and we decided that we want to have a Postfix server sit in front of it to act as the mail gateway.

So I built the Postfix server and to test, I telnet'd to the box internally, and it works just fine.

If I try to telnet externally, I would get the following prompt:

220 ********************************* (I didn't place those asteriks in...it just came up that way). And it make it worse, it thinks all the commands are not implemented (i.e. error message 500 unrecognized command).

Now, before you point the finger at Postfix and say it has nothing to do with the PIX....

As a test, I completely cut the Postfix box out of the equation and simply placed the Exchange server out in the wild.

I got the exact same error messages!!!

This is what leads me to believe that the PIX is "inspecting" the traffic, or doing something to prohibt the use of it.


does anyone have any thoughts or suggestions?

Many thanks!!

Sam
 
Does version 7 have "smtp fixup"? That's what it does. It's not an error, it is restricting you to the 7 "safe" SMTP commands. Remove the fixup and you'll be able to use all the ESMTP stuff.
 
Well, I just checked and I had inspect smtp turned on.

I turned it off, and guess what?

I worked!

So that leads me to believe that I dont really know the 7 "safe" SMTP commands!

I thought helo, mail from, rcpt to, data....were all acceptable??

What am I missing here because I would like to use every security feature I have at my disposel, but I wont if Im not convinced that it wont lock out the rest of the world.
 
hmm, wierd. I tried all those commands but it just replaces them with NOOP. Well, in the mean time, I'm going to keep it disabled until I can figure out its issue.

Thanks guys!
 
one thing to remember when you use a std. telnet through pix for smtp testing, you need line mode, not char mode, and you can't use backspace to correct any typos, that will garble the commands.

Network Systems Engineer
CCNA/CQS/CCSP/Infosec
Check the danish Cisco CSA Forum here :
 
Good point, but do clients like PuTTY allow you to switch modes?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top