Re: How to Block all outbound SMTP except Exchange Server



On Sat, 21 Jul 2007 15:43:39 -0000, GNY wrote:

On Jul 20, 10:31 pm, gc...@xxxxxxxxxxxxx wrote:
On Jul 20, 5:37 pm, "Ross" <nos...@xxxxxxxx> wrote:

Hi there,
I have a Cisco PIX 515e version 7.2, and I have an Exchange email server
inside the firewall, which are all working well.
Right now, I'm trying to block all outgoing SMTP traffic (over port 25),
except from my company's Exchange server.
Any idea about how to do this is appreciated.
Ross

access-list SMTP-CONTROL permit tcp host 10.1.1.1 any eq smtp ! Where
10.1.1.1 is the IP address of Exchange
access-list SMTP-CONTROL deny tcp any any eq smtp
access-list SMTP-CONTROL permit ip any any ! implicit deny any any
!
access-group SMTP-CONTROL in interface inside
!

Since the access-list gets executed in order, line one runs first and
wont make it to line two unless it is a TCP connection on port 25 with
a different IP address. Remember if anyone trys to send any mail
except the exchange server it will be blocked.

Sorry to thread jack .. But on an ASA if I was trying to do something
similar would I have to assign this access-list to an interface? Or is
this only for IOS routers where you have to assign the ACL to an
interface?

Thanks and sorry again ..

GNY


The example above is for a Pix version 7.x, which is essentially the same
as an ASA. So yes, you have to apply the access-list to an interface.

Chris.
.



Relevant Pages

  • Re: Outlook Slow
    ... Directory DRS Interface:YES ... Server STORE EMSMDB Interface:YES ... Server STORE ADMIN Interface:YES ... Exchange 2000 Windows 2000 Connectivity Through Firewalls ...
    (microsoft.public.exchange2000.clients)
  • Re: Server braucht extrem lange für einen Neustart
    ... >> dein Server ist multihomed und ein RRAS interface, ... > RRAS, noch am DNS, noch an VM Ware liegt, da das alles ohne Probleme ... na dann weisst du ja woran es liegt: Dein Exchange sucht wahrscheinlich auf ... dem falschen Interface nach dem DC und kann den nicht finden. ...
    (microsoft.public.de.exchange)
  • Re: DMZ setup on firewall
    ... The ouside interface of the PIX only lets 80 and 443 throught to the ... OWA Exchange server. ... Exchange server and put in on a web server in the DMZ. ...
    (comp.security.firewalls)
  • =?utf-8?Q?Re:_EBS_2008_verst=C3=A4ndnis_Frage_T?= =?utf-8?Q?MG_zu_Exchange?=
    ... Ich habe nun die Regel angepasst und nicht mehr auf das interne Interface ... Der Security Server des EBS 2008 ist nicht nur Application Layer Firewall mittels TMG MBE, sondern auch gleichzeitig Edge-Transport Server in der Exchange Topologie. ...
    (microsoft.public.de.german.backoffice.smallbiz)
  • Re: How to Block all outbound SMTP except Exchange Server
    ... I have a Cisco PIX 515e version 7.2, and I have an Exchange email server ... access-list SMTP-CONTROL permit tcp host 10.1.1.1 any eq smtp! ... similar would I have to assign this access-list to an interface? ...
    (comp.dcom.sys.cisco)