Re: Exchange and Firewall

From: Denis McDowell [MSFT] (denismcd_at_online.microsoft.com)
Date: 05/24/04


Date: Mon, 24 May 2004 15:18:27 -0400

Exchange will accept mail as long as the TCP connection and the SMTP
transaction reach the server. In this case, the firewall is somehow
preventing maiflow.

-- 
Denis McDowell [MSFT]
"Danny Sanders" <Danny.Sanders@cpcNOmedSPAM.org> wrote in message
news:%23RCDB$aQEHA.2468@tk2msftngp13.phx.gbl...
> We are running Exchange 2000 on Windows 2000 advanced server. We had been
> running a Netscreen 10 firewall to protect the network. Last week we got a
> Cisco Pix 506E to replace the Netscreen 10. I was able to get the Cisco
506E
> configured to the point where we were able to browse the Internet and send
> e-mail. With the Cisco Pix installed and using Cisco tech support (2
> different techs).
> The Cisco techs used telnet to get into the firewall and checked the
config.
> According to the Cisco techs everything is setup correctly for our
internal
> email server to receive email on it's "public IP address" and forwarded to
> the Exchange server on our private network.
>
> The problem is we still can not receive email. If I change the firewall
back
> to the Netscreen, we get email. The Cisco tech used telnet to access the
> Exchange server with the Netscreen firewall in place and is able to
connect.
> Using telnet with the Cisco firewall in place results in a build of the
> inbound connection immediately followed by a tear down, duration is
0:00:00
> and the server sends a FIN.
>
> Here is an excerpt of the log Cisco sent with the internal & external IP
> addresses changed:
>
>
> 302013: Built inbound TCP connection 1543 for outside:218.54.27.20/3382
> (218.54.27.20/3382) to inside:X.X.X.X/25 (67.95.237.52/25)
>
> 302014: Teardown TCP connection 1543 for outside:218.54.27.20/3382 to
> inside:X.X.X.X/25 duration 0:00:00 bytes 0 TCP FINs
>
> 111009: User 'enable_15' executed cmd: show logging
>
> 302015: Built outbound UDP connection 1544 for outside:209.116.241.10/53
> (209.116.241.10/53) to inside:X.X.X.X/31232 (67.95.237.52/31232)
>
> 302016: Teardown UDP connection 1544 for outside:209.116.241.10/53 to
> inside:X.X.X.X/31232 duration 0:00:01 bytes 183
>
> 302015: Built outbound UDP connection 1545 for outside:209.116.241.10/53
> (209.116.241.10/53) to inside:X.X.X.X/31233 (67.95.237.52/31233)
>
> 302016: Teardown UDP connection 1545 for outside:209.116.241.10/53 to
> inside:X.X.X.X/31233 duration 0:00:01 bytes 202
>
> 302015: Built outbound UDP connection 1546 for outside:209.116.241.10/53
> (209.116.241.10/53) to inside:X.X.X.X/31234 (67.95.237.52/31234)
>
> 302016: Teardown UDP connection 1546 for outside:209.116.241.10/53 to
> inside:X.X.X.X/31234 duration 0:00:01 bytes 186
>
>
>
> Any Ideas why Exchange will accept email through the Netscreen Firewall
and
> Not the Cisco Pix?
>
>
>
> TIA
>
> DDS
>
>
>
>
>
>


Relevant Pages

  • Re: Unable to Receive Email from the internet
    ... Are you running this on Longhorn server? ... Test from outside your firewall: ... Exchange Server 2007: internet email without Edge ... looking at the firewall inbound rules on my LHS. ...
    (microsoft.public.exchange.setup)
  • Re: Open ports?
    ... You can't install Exchange without IIS. ... This server isn't going to be as secure as possible. ... >>> However, if this is your domain controller, putting a firewall between ...
    (microsoft.public.win2000.security)
  • Re: OMA?
    ... You would need to open up port 80 to the Exchange server only. ... > would I have to open up port 80 on my firewall, ...
    (microsoft.public.exchange.connectivity)
  • Re: SBS2008 - Exchange 2007 + Connection Control
    ... But then why not do it in Exchange if the facility is there to do ... but the fact that you can't do this in your firewall should ... Microsoft Exchange> Server Configuration> Hub Transport> ... Currently this would appear by default to permit connections ...
    (microsoft.public.windows.server.sbs)
  • Re: SBS2008 - Exchange 2007 + Connection Control
    ... But then why not do it in Exchange if the facility is there to do it? ... as it will make troubleshooting a huge PITA. ... but the fact that you can't do this in your firewall should be ... Microsoft Exchange> Server Configuration> Hub Transport> ...
    (microsoft.public.windows.server.sbs)

Loading