Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

MSS inconsistencies on SMTP communication

Getting a FLOOD, huge flood of

" reason: MSS exceeded, MSS 1300, data 1360" on Port 25

running Pix 7.0.4 code.

What is up with this? Have seen some of these in the past, but nothing like the 1 to 3 every second. I think someone is trying to run a SMTP exploit on my port 25. I am not getting these on port 80. Also have not had this huge amount of MSS reject in the past.

Suggestions?

3 REPLIES

Re: MSS inconsistencies on SMTP communication

This is rarely caused by exploits, this usually problems with the TCP settings on the server/client etc. Have a look at:

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00804c8b9f.shtml

As you see Cisco has changed the default from 'deny' to 'allow' due to excessive user complaints starting from release 7.2(4)

http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/ef_72.html#wp1758645

Regards

Farrukh

Community Member

Re: MSS inconsistencies on SMTP communication

Tech note applies to http sites. I am having an issue with port 25 inbound. My quesiton is can I apply the same to port 25 to bypass the MSS messages.

Re: MSS inconsistencies on SMTP communication

Yes why not.

Regards

Farrukh

191
Views
0
Helpful
3
Replies
CreatePlease to create content