accessing mail server from Internet via pix

Unanswered Question
Mar 5th, 2009
User Badges:

Hi,


i cannot access the mail server from internet. can anyone help.


following is the setup:


PIX outside interface connected to INTERNET.

PIX inside interface connected to LAN Router.

Router interface connected to switch.

Email server having ip 10.2.1.5 connected to switch.



at pix:

access-list 100 extended permit tcp any host 210.x.x.x eq smtp

access-list 100 extended permit tcp any host 210.x.x.x eq ftp


access-group 100 in interface outside.


static (inside,outside) 210.x.x.x 10.2.1.5 netmask 255.255.255.255

static (inside,outside) 210.X.x.x 10.2.1.6 netmask 255.255.255.255

Problem:


can't access the email server via 210.X.x.x from internet.


syslog message shows that


deny udp source outside-----by access group 100.


can anyone help.


Thanks in advance







  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
JamesLuther Thu, 03/05/2009 - 01:56
User Badges:
  • Silver, 250 points or more

Hi,


The syslog message is saying "deny udp source", however ACL 100 only has TCP statements. Try to find out exactly what the UDP traffic is and allow it if needed.



Regards

seekhpar121 Thu, 03/05/2009 - 03:08
User Badges:

Also i recived following message:

TCP access denied by ACL from :ip from internet/18989 to outside:pix interface(public) ip/80



vikram_anumukonda Thu, 03/05/2009 - 05:28
User Badges:
  • Bronze, 100 points or more

are you seeing any hits against the access-list 100 extended permit tcp any host 210.x.x.x eq smtp ace


Actions

This Discussion