Re: Delivery to the following recipients has been delayed when behind firewall

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Sorry about the tl;dr question. If anyone did read it and is
interested in the solution, the Cisco PIX was doing stateful
application inspection (fixup) on ESMTP. From what I understand, when
applied to outgoing e-mail, the inspection modifies the e-mails in
order to "protect" sensitive information. I also got this from the
Cisco website after figuring out that was the problem.

"The fixup protocol smtp command enables the Mail Guard feature. This
restricts mail servers to receiving the seven minimal commands defined
in RFC 821, section 4.5.1 (HELO, MAIL, RCPT, DATA, RSET, NOOP, and
QUIT). All other commands are rejected.

Microsoft Exchange server does not strictly comply with RFC 821
section 4.5.1, using extended SMTP commands such as EHLO. PIX Firewall
will convert any such commands into NOOP commands, which as specified
by the RFC, forces SMTP servers to fall back to using minimal SMTP
commands only. This may cause Microsoft Outlook clients and Exchange
servers to function unpredictably when their connection passes through
PIX Firewall."

So if you run an Exchange server, and you are using a Cisco PIX, do
NOT use the [fixup protocol smtp 25] or for 7.x in our case [policy-
map] \ [class] \ [inspect ESMTP] because it may make things act screwy.
.



Relevant Pages

  • Re: User Auditing
    ... We have servers in our environment by which multiple people ... can issue commands as either themselves or as root. ... And the pam bit that logs keystrokes to auditd does log every keypress. ... Subject: User Auditing ...
    (RedHat)
  • Re: How to program in Python to run system commands in 1000s of servers
    ...  Want to program in python to run sysadmin ... commands across 1000s of servers and gather the result in one place. ... Many times the commands need to be run as root. ... There are a bajillion ways to do it badly, but SSH sounds like the ...
    (comp.lang.python)
  • Re: smtp auth behind firewall
    ... My problem is if I connect over the lan I can use smtp auth ... Disable SMTP filtering on cisco pix. ... featuring a variety of commands defined in RFC 1869. ... has been the path to exploit a security hole in recent times. ...
    (comp.mail.sendmail)
  • Re: certificate not trusted even though I imported it
    ... I did the following commands to generate a ... I copied the crt files from the servers to the other and ... imported cbs2's cert into the cacerts file on cbs1 (I did this from the ...
    (comp.lang.java.programmer)
  • Weird FTP issue???
    ... using such commands as portsnap, portaudit, fetch, etc. ... First off, I'm running FreeBSD v6.1. ... one of the servers has been ... not being able to get a connection with the remote FreeBSD server. ...
    (freebsd-questions)