Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Webcast-Catalyst9k
New Member

Connecting to the mail server from the DMZ

When trying to send an e-mail from the SMTP server on the DMZ to the mail server on the inside network, the mail is not delivered. Is this due to the fact that the firewall can not route the message to the mail server? If so how can I get around this problem

10 REPLIES

Re: Connecting to the mail server from the DMZ

Hi

AFAIK since DMZ is considered to be a low secured zone when compared to Inside network you need to allow/permit the SMTP traffic from DMZ to flow to inside network.

But its the other way around when you think off from Inside to DMZ in which you dont need to enable or open required ports.

regs

Re: Connecting to the mail server from the DMZ

Hi,

How is the MX record resolved for the inside mail servers domain. ?

Where is the DNS server located?

Check out this URL for DNS rewrite functionality, which may be helpful in your case

http://www.cisco.com/en/US/products/ps6120/products_configuration_guide_chapter09186a0080640337.html#wp1350877

HTH

-VJ

New Member

Re: Connecting to the mail server from the DMZ

The DNS server is located on the ISP's network.

New Member

Re: Connecting to the mail server from the DMZ

The MX record is resolved by using a DNS server outside of the internal network. I read the information from the link that you provided, however I don't think it explains a situation where the host computer on the dmz is trying to route e-mail to a mail server that resides on the inside interface.

Thanks for your help so far,

Joey

New Member

Re: Connecting to the mail server from the DMZ

Are there any more suggestions for my problem?

Thanks,

Joey

Re: Connecting to the mail server from the DMZ

Hi Joe,

As pointed out by the previous poster, is there proper access configured in your firewall to allow the smtp connection from the server on the DMZ to the mail server on the inside network.?

If you could provide the firewall config snapshot ( after removing the sensitive informations..public ip.etc), we would be able to have a look and help you to correct any problems in the configuration. Provide ip address details on the involved servers also.

You can quickly check whether SMTP connection to inside server is allowed from server on DMZ as follows.

On the server located in DMZ, initiate a telnet connection to the inside server ip on port 25.( telnet 25 ). If the telnet session responds then there is no issue at firewall level and you need check on the settings of mail server configurations.

HTH

-VJ

New Member

Re: Connecting to the mail server from the DMZ

Hello,

I tried telneting on port 25 to 199.199.199.70 from 172.17.17.111 and that did not work. The host ( 172.17.17.111) is trying to route mail to the mail server (199.199.199.70).

Also here is the config file.

Re: Connecting to the mail server from the DMZ

You are missing a few things, NAT, conduit and alias from your configuration.

You need to define a NAT rule. Conduit to allow the traffic between the servers. Alias configured to do DNS doctoring as the DMZ server tries to communicate with the inside server using the global IP address.

Can you configure the following and try.

static (inside, dmz) 172.17.17.11 172.17.17.11 netmask 255.255.255.255

conduit permit tcp host 172.17.17.11 host 172.17.16.10 eq smtp

alias (dmz) 172.17.16.10 199.199.199.70 255.255.255.255

HTH,

Sundar

New Member

Re: Connecting to the mail server from the DMZ

Thanks Sundar,

I tried the configuration changes that you suggested. However I think the correct address for the host on the dmz should have been 172.17.17.111 and i think the conduit command should have the host addresses reversed. I tried it both ways and I still could not telnet to the mail server (172.17.16.10)using port 25 from the host on the dmz. Here is a copy of the new config with the changes that you recommended.

New Member

Re: Connecting to the mail server from the DMZ

Hello Sundar are you there?

251
Views
0
Helpful
10
Replies
CreatePlease to create content