Exchange and Firewall

From: Danny Sanders (Danny.Sanders_at_cpcNOmedSPAM.org)
Date: 05/24/04


Date: Mon, 24 May 2004 10:52:01 -0600

We are running Exchange 2000 on Windows 2000 advanced server. We had been
running a Netscreen 10 firewall to protect the network. Last week we got a
Cisco Pix 506E to replace the Netscreen 10. I was able to get the Cisco 506E
configured to the point where we were able to browse the Internet and send
e-mail. With the Cisco Pix installed and using Cisco tech support (2
different techs).
The Cisco techs used telnet to get into the firewall and checked the config.
According to the Cisco techs everything is setup correctly for our internal
email server to receive email on it's "public IP address" and forwarded to
the Exchange server on our private network.

The problem is we still can not receive email. If I change the firewall back
to the Netscreen, we get email. The Cisco tech used telnet to access the
Exchange server with the Netscreen firewall in place and is able to connect.
Using telnet with the Cisco firewall in place results in a build of the
inbound connection immediately followed by a tear down, duration is 0:00:00
and the server sends a FIN.

Here is an excerpt of the log Cisco sent with the internal & external IP
addresses changed:

302013: Built inbound TCP connection 1543 for outside:218.54.27.20/3382
(218.54.27.20/3382) to inside:X.X.X.X/25 (67.95.237.52/25)

302014: Teardown TCP connection 1543 for outside:218.54.27.20/3382 to
inside:X.X.X.X/25 duration 0:00:00 bytes 0 TCP FINs

111009: User 'enable_15' executed cmd: show logging

302015: Built outbound UDP connection 1544 for outside:209.116.241.10/53
(209.116.241.10/53) to inside:X.X.X.X/31232 (67.95.237.52/31232)

302016: Teardown UDP connection 1544 for outside:209.116.241.10/53 to
inside:X.X.X.X/31232 duration 0:00:01 bytes 183

302015: Built outbound UDP connection 1545 for outside:209.116.241.10/53
(209.116.241.10/53) to inside:X.X.X.X/31233 (67.95.237.52/31233)

302016: Teardown UDP connection 1545 for outside:209.116.241.10/53 to
inside:X.X.X.X/31233 duration 0:00:01 bytes 202

302015: Built outbound UDP connection 1546 for outside:209.116.241.10/53
(209.116.241.10/53) to inside:X.X.X.X/31234 (67.95.237.52/31234)

302016: Teardown UDP connection 1546 for outside:209.116.241.10/53 to
inside:X.X.X.X/31234 duration 0:00:01 bytes 186

Any Ideas why Exchange will accept email through the Netscreen Firewall and
Not the Cisco Pix?

TIA

DDS



Relevant Pages

  • Re: Exchange and Firewall
    ... Exchange will accept mail as long as the TCP connection and the SMTP ... > We are running Exchange 2000 on Windows 2000 advanced server. ... We had been> running a Netscreen 10 firewall to protect the network. ... Last week we got a> Cisco Pix 506E to replace the Netscreen 10. ...
    (microsoft.public.exchange.connectivity)
  • Firewall Admin Needed!
    ... Position: CISCO FIREWALL ADMIN ... Installation and administration of the following firewall server ... and installation of the following VPN client technologies:(Symantec VPN ...
    (comp.security.firewalls)
  • Re: Exchange and Firewall
    ... On the Cisco PIX device manager, all references to our internal Exchange ... > transaction reach the server. ... In this case, the firewall is somehow ...
    (microsoft.public.exchange.connectivity)
  • Re: AIX routing
    ... Looks like you have an asymetric routing problem. ... The cisco communicates over a private network to the 6H1, ... Apache+Proxy box in between the firewall and IBM machine, ... At the server it is another address which is resolved locally. ...
    (AIX-L)
  • Cisco Security Advisory: Unity Vulnerabilities on IBM-based Servers
    ... Cisco Security Procedures ... direct IBM branding and installed with the Cisco Unity Server image disk ... Manager address and DHCP server address (no local user account "bubba"): ...
    (NT-Bugtraq)

Loading