Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

AJ: PIX with mail server problem

I have a PIX 501 running V6.1(2). Im using a DSL line connected to the PIX, then from the PIX i connect 2 servers with 2 LAN cards. The other cards are connected to the inner LAN ( The first server runs proxy to allow the inner network to surf the internet and the second server is a mail server. Heres a trascript of my configuration:







Mail( / Proxy(



access-list 100 permit icmp any any echo-reply

access-list 100 permit icmp any any time-exceeded

access-list 100 permit icmp any any unreachable

access-list 100 permit tcp any host eq smtp

ip address outside

ip address inside

global (outside) 1

nat (inside) 1 0 0

static (inside, outside)

route outside

access-group 100 in interface outside

The problem is when I inject static, access-list, access-group then clear xlate, the mail server will not be able to surf, send and accept email (Proxy still works fine). The email server works fine when given with a public IP and connected directly to the DSL line. Anyone got an explanation to this?

New Member

Re: AJ: PIX with mail server problem


What's the default gateway on the mail server?

New Member

Re: AJ: PIX with mail server problem

default gateway is the inside address of the PIX which is

New Member

Re: AJ: PIX with mail server problem

Hi Allan,

1- Check if you have a static translation (show xlate) for your mail server

2- If not, try the more generic command format for your static entry.

static (inside, outside) netmask 0 0

3- If it's not working yet, use debug in combination with Syslog to see what's going through the PIX and what's rejected.

4- Another test, are you able to surf (Web) from your mail server, it should be?

Another comment, your inside network is largely open, you should restrict it by applying access-list to inside interface.



New Member

Re: AJ: PIX with mail server problem

When you make changes did you check whether the access group command is still there. when you remove the access-list and put it back you have to put back the access-group command as well.

New Member

Re: AJ: PIX with mail server problem

Thanks all for your response. I got it working now. The problem there was that my mail server uses ESMTP (Microsoft Excahange) . I just turn off the Mail Guard (no fixup protocol smtp) since PIX doesnt support the non-standard ESMTP commands while allowing static entry for mail protocol. Now its working. Thats one good lesson ive learned.