IOS Firewall Configuration for PoP3

Unanswered Question
Dec 19th, 2007
User Badges:


I have configured a Cisco 1841 IOS firewall. All works well except for PoP3 traffic. If I take out the inspect rule applied outbound on the outside interface and the access list applied inbound to the outside interface PoP3 works.

So i know for sure my config is wrong.

Can someone help pls..

Here is my config:

ip inspect name firewall ftp

ip inspect name firewall http

ip inspect name firewall dns

ip inspect name firewall tcp router-traffic

ip inspect name firewall udp router-traffic

ip inspect name firewall https

ip inspect name firewall smtp

ip inspect name firewall ssh

ip inspect name firewall telnet

ip inspect name firewall pop3

interface FastEthernet0/0

ip address

ip nat inside

interface Serial0/0/0

no ip address

encapsulation frame-relay IETF

no ip route-cache cef

no ip route-cache

no fair-queue

frame-relay lmi-type ansi


interface Serial0/0/0.1 point-to-point

ip address 255.255.252

ip access-group 100 in

no ip redirects

no ip proxy-arp

ip inspect firewall out

ip nat outside

ip nat inside source list 101 interface Serial0/0/0.1 overload

access-list 100 deny ip host any

access-list 100 deny ip any

access-list 100 permit icmp any any echo-reply

access-list 100 permit icmp any time-exceeded

access-list 100 permit icmp any packet-too-big

access-list 100 permit icmp any traceroute

access-list 100 permit icmp any unreachable

access-list 101 permit ip any

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
p.holley Wed, 12/19/2007 - 14:12
User Badges:

This is what I got when I enabled audit-trail for pop3

Dec 19 2007 17:50:12.151 UTC: %FW-6-SESS_AUDIT_TRAIL: Stop pop3 session: initiator ( sent 70 bytes -- responder ( sent 1577 bytes

This is the error message the user got on their PC.

Your message did not reach some or all of the intended recipients.

Subject: test

Sent: 12/19/2007 5:51 PM

The following recipient(s) could not be reached:

'[email protected]' on 12/19/2007 5:51 PM

550 5.7.1 <[email protected]>... Relaying denied. IP name possibly forged [] is the ip address of my router to the public internet.

Any ideas

p.holley Wed, 12/19/2007 - 14:51
User Badges:

Also this is for only outgoing emails, incoming works.


This Discussion