Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Limit outbound SMTP connection

I need to limit outbound SMTP connections for internal hosts on Pix 506e. I have to allow each host to make then, but after a host makes say 10 in a certain amount of time, I want to block it. This is for a Liberal Arts dorm network and the ISP is complaining about addresses from the dorm network sending spam. I can't block port 25 altogether as the other students will still need to send email.....any ideas? Basic PIX config, no static coming in, all NAT/PAT going out.



Re: Limit outbound SMTP connection

A PIX is not made to do that. Control SMTP usage by hosting a SMTP server at your location and configuring the PIX to only allow that server SMTP out.

New Member

Re: Limit outbound SMTP connection

You should be able to block port 25 altogether unless you have an email server in the same subnet - in which case you would allow smtp from the mail server and block from everyone else. Clients do not send email on port 25 (or should not - ever). Clients connect to mail servers to send email and they connect to the mail server using pop3 or web interface which are ports 110 or 80 respectively. Port 25 should always be blocked outbound from anything that is not a mail server.