Guest_imported
New member
- Jan 1, 1970
- 0
I have a PIX 515 with 3 interfaces.
My MailServer ( a cobalt Raq4r) is in the DMZ.
My problem happend when i send email, it takes sometimes more than 30 sec for the mail to be sent to the Cobalt.
In my pix syslog, every time i send a mail (from my PC 172.18.100.125 - inside) i have this message twice :
%PIX-2-106001: Inbound TCP connection denied from 192.168.0.3/1114 to 172.18.100.125/113 flags SYN on interface dmz
192.168.0.3 is my MailServer
This a part of my PIX config
ip address outside 196.121.122.73 255.255.255.0
ip address inside 172.18.100.1 255.255.0.0
ip address dmz 192.168.0.1 255.255.255.0
ip audit info action alarm
ip audit attack action alarm
arp timeout 14400
global (outside) 1 196.121.122.75-196.121.122.76
global (outside) 1 196.121.122.74
global (dmz) 1 192.168.0.10-192.168.0.20
nat (inside) 1 172.18.0.0 255.255.0.0 0 0
static (dmz,outside) 195.101.102.77 mailserver netmask 255.255.255.255 0 0
conduit permit icmp any any
conduit permit tcp host 196.121.122.77 eq smtp any
conduit permit tcp host 196.121.122.77 eq pop3 any
route outside 0.0.0.0 0.0.0.0 196.121.122.78 1
Thank in advance for your help.
olly@wanadoo.fr
My MailServer ( a cobalt Raq4r) is in the DMZ.
My problem happend when i send email, it takes sometimes more than 30 sec for the mail to be sent to the Cobalt.
In my pix syslog, every time i send a mail (from my PC 172.18.100.125 - inside) i have this message twice :
%PIX-2-106001: Inbound TCP connection denied from 192.168.0.3/1114 to 172.18.100.125/113 flags SYN on interface dmz
192.168.0.3 is my MailServer
This a part of my PIX config
ip address outside 196.121.122.73 255.255.255.0
ip address inside 172.18.100.1 255.255.0.0
ip address dmz 192.168.0.1 255.255.255.0
ip audit info action alarm
ip audit attack action alarm
arp timeout 14400
global (outside) 1 196.121.122.75-196.121.122.76
global (outside) 1 196.121.122.74
global (dmz) 1 192.168.0.10-192.168.0.20
nat (inside) 1 172.18.0.0 255.255.0.0 0 0
static (dmz,outside) 195.101.102.77 mailserver netmask 255.255.255.255 0 0
conduit permit icmp any any
conduit permit tcp host 196.121.122.77 eq smtp any
conduit permit tcp host 196.121.122.77 eq pop3 any
route outside 0.0.0.0 0.0.0.0 196.121.122.78 1
Thank in advance for your help.
olly@wanadoo.fr