OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Inbound connections through Cisco PIX failing?

From: Erik Forsberg (forsberg+pfucendio.se)
Date: Wed Jun 02 2004 - 02:42:21 CDT


Hi!

I have a problem at a customer site, with a newly installed Postfix
version 2.1.1. The Postfix machine is behind a Cisco PIX firewall, as
seen by trying to connect from the outside:

220 SMTP/cmap ready_________________________________________________________________

Now, the problem is that mail from hotmail, and quite a few other
domains, doesn't arrive as expected. The only thing seen in the
Postfix logs are entries like these:

May 28 04:16:27 eskil postfix/smtpd[14289]: connect from bay17-f42.bay17.hotmail.com[64.4.43.92]
May 28 04:16:28 eskil postfix/smtpd[14289]: disconnect from bay17-f42.bay17.hotmail.com[64.4.43.92]

There is nothing inbetween the two lines above for that particular
smtpd process.

I suspect this is a problem with the Cisco PIX. Unfortunately, I don't
know the exact version of the PIX, nor have I been able to put
hotmail.com in the debug_peer_list to get more info out of Postfix,
and currently the customer has gone back to his old Sendmail
configuration (which works flawlessly for all inbound connections).

Any ideas on this? I know there was problems with Postfix _sending_
mail to other servers behind a Cisco PIX, a few years ago, but I
haven't heard of the other direction. On the other hand, I've been off
this list a while.. I couldn't find any relevant Google hits or FAQ
entries.

Regards,
\EF
--
Erik Forsberg Telephone: +46-13-21 46 00
Cendio AB Web: http://www.cendio.com