Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

Not recieving email from one company

As of last Friday, we can not recieve email from one company (that we know of). I don't remember making any changes to the firewall except adding pptp to the inpection list. I have removed ESMTP from the inspection list and still can't recieve their email.

This is what I see in my logs:

Jun 16 2008 13:55:48: %ASA-6-302013: Built inbound TCP connection 1969454 for Outside:70.98.248.217/11877 (70.98.248.217/11877) to DMZ:SpamFW/25

generic_num=6, specificTrap_num=1, specificTrap_name=, clogHistFacility.0=20, clogHistSeverity.0=7, clogHistMsgName.0="Syslog Trap", clogHistMsgText.0="<166>Jun 16 2008 13:55:48: %ASA-6-302013: Built inbound TCP connection 1969454 for Outside:70.98.248.217/11877 (70.98.248.217/11877) to DMZ:SpamFW/25 (66.193.105.213/25)", clogHistTimestamp.0=69394600

Jun 16 2008 13:55:48: %ASA-6-302014: Teardown TCP connection 1969454 for Outside:70.98.248.217/11877 to DMZ:SpamFW/25 duration 0:00:00 bytes 0 TCP Reset-O

generic_num=6, specificTrap_num=1, specificTrap_name=, clogHistFacility.0=20, clogHistSeverity.0=7, clogHistMsgName.0="Syslog Trap", clogHistMsgText.0="<166>Jun 16 2008 13:55:48: %ASA-6-302014: Teardown TCP connection 1969454 for Outside:70.98.248.217/11877 to DMZ:SpamFW/25 duration 0:00:00 bytes 0 TCP Reset-O", clogHistTimestamp.0=69394600

Any help would be appreciated,

Thanks

Shawn

3 REPLIES

Re: Not recieving email from one company

Are you sure this is an issue with the firewall?

It seems your anti-spam software is resetting connections from mail server 70.98.248.217, perhaps this host exists is in its Black list or something?

Regards

Farrukh

Community Member

Re: Not recieving email from one company

Thanks for your reply, but it ended up being a problem with the sender. They did not tell me they were having other mail related issues and just decided to blame us. The 70.98.248.217 address was their sending mail host, and it would send an immediate reset after establishing the connection.

Re: Not recieving email from one company

Ahh OK, thanks for the update :)

Regards

Farrukh

129
Views
5
Helpful
3
Replies
CreatePlease to create content