Fixup protocol smtp 25

Answered Question
Jul 14th, 2004

The Exchange Mail servers run ESMTP.

The only way the PIX Firewall allows ESMTP is to disable the fixup protocol smtp 25.

Does this not create security expsoures on the firewall for SMTP.

Is there a way to customize mailguard to protect SMTP and still allow ESMTP through.

regds

Johnny

I have this problem too.
0 votes
Correct Answer by scoclayton about 9 years 9 months ago

It is a free upgrade if you have a smartnet contract on your PIX. A Smartnet contract entitles you to free software upgrades on the convered hardware. Hope this helps explain matters.

Scott

  • 1
  • 2
  • 3
  • 4
  • 5
Average Rating: 3 (2 ratings)
jmia@ohgroup.co.uk Wed, 07/14/2004 - 04:11

Johnny

Yes you are correct, by disabling the SMTP fixup protocol you are creating a SMTP security problem. I don't believe there is a way of customizing mailguard to protect SMTP and still allow ESMTP.

You can only have one or the other, i.e. fixup protocol SMTP 25 OR no fixup protocol SMTP 25. The PIX is doing its job correctly and if you are running ESMTP then I would suggest that you fine tune you ESMTP server and not the PIX! I am not a Microsoft guy so will not be able to advise on fine tuning an ESMTP server but there are lots of information on this on the web just try Google, i.e. search for PIX ESMTP problems.

Hope this helps a little.

Jay

scoclayton Wed, 07/14/2004 - 05:04

As an FYI, the feature requests have been heard and we are finally adding an ESMTP inspection engine to PIX 7.0 code which is due out towards the end of the year.

Scott

johnnys@za.ibm.com Wed, 07/14/2004 - 05:24

Hi Scott,

Thanks for the info.

I'm assuming there will be a charge to upgrade from 6.3 to 7.0 or would this be a free upgrade.

regds

Johnny

Correct Answer
scoclayton Wed, 07/14/2004 - 08:57

It is a free upgrade if you have a smartnet contract on your PIX. A Smartnet contract entitles you to free software upgrades on the convered hardware. Hope this helps explain matters.

Scott

Actions

Login or Register to take actions

This Discussion

Posted July 14, 2004 at 3:21 AM
Stats:
Replies:5 Avg. Rating:3
Views:372 Votes:0
Shares:0
Tags: No tags.

Discussions Leaderboard