Re: SMTP traffic getting through router and firewall



it is allowed by the ACL:

*Sep 14 18:37:52.195: %SEC-6-IPACCESSLOGP: list filterin permitted tcp
206.114.4
7.212(1890) (FastEthernet0/1 00a0.c815.e26d) -> PUBLIC IP(25), 1 packet

but it doesn't make it out of the router. I have a static route to
send it to the firewall. What could be getting in the way?

Thanks.

K.J. 44 wrote:
I am able to telnet to my SMTP server from my router and I can see a
permit match on the ACL of my outer interface of my router when someone
from outside telnet's in, but their connection doesn't work.

ROUTER --------- FIREWALL --------SMTP Server


Is there a way to see if the packet is making it through the router and
to the ASA? I tried debug smtp but nothing came up even when the
connection was successful from the router. There are no ACLs outbound
on my inside interface of the router.

Internet ---------Router -------------Firewall --------SMTP Server
Works from here------------------->
Works to here----|
ACL match permits into outside interface.

Thanks.

.



Relevant Pages

  • Re: Site-to-Site VPN client routing question - clients at branch office not able to acce
    ... You can check this by making sure that the dd interface on the answering router has changed to connected status. ... Your DC might only have one NIC, but as soon as your VPN connection is made it has two IP addresses, so you get all sorts of problems. ... select the demand-dial interface from the dropdown list. ...
    (microsoft.public.windows.server.networking)
  • Re: Connection stalls until I do ping/traceroute in router
    ... If it was not unique, and another host shared that address, the ARP table on your system would map the gateway's IP address to the MAC address of the gateway "some of the time", and map it to the MAC address of the host sharing the IP address at "other times". ... If you connected the LAN interface of your gateway router to the LAN interface of another device which used the same default IP address for its admin interface, ... between your ISP and their connection to the interknot. ...
    (alt.internet.wireless)
  • Re: Server 2008 RAS Demand Dial VPN
    ... connection gets and keeps it's IP before the demand dial connection starts. ... Demand-Dial Interface Is Unreachable: ... You can enable a Windows NT router to request an IP address when you connect ...
    (microsoft.public.windows.server.networking)
  • Re: Windows 2000 RAS Server and a Cisco Client Router
    ... You need to use the method which a router to router connection uses. ... This involves setting up a demand-dial interface on the server. ... dropdown list as the interface to link with the route. ...
    (microsoft.public.win2000.ras_routing)
  • Re: routing problem site to site
    ... a nat interface is enabled, site 2 is just a dmz behind a router. ... are both dd interfaces bound to the connection ... are the static routes added to the ...
    (microsoft.public.windows.server.networking)