My Cisco ASA is mangling legitimate SMTP traffic

I set up my ASA-5520 (PIX) with the obvious rule to allow incoming SMTP traffic. Additionally, I have a rule the permits any traffic from the mail server to the Internet.

My problem is that the firewall is behaving like a wise guy, distorting SMTP dialogs, by replacing some lines with a bunch of Xs, followed by a sequential alphabetic letter.

Let's examine the dialogs telneting from server A to B, and then from server B to A.

The following lines:

EHLO abc.com

250-postino.example.com Hello
formatting link
[12.34.56.78], pleased to meet you 250-ENHANCEDSTATUSCODES 250-PIPELINING 250-EXPN 250-VERB 250-8BITMIME 250-SIZE 250-DSN 250-ETRN 250-DELIVERBY 250 HELP

are transliterated into:

250-ENHANCEDSTATUSCODES 250-PIPELINING 250-XXXA 250-XXXB 250-8BITMIME 250-SIZE 250-DSN 250-ETRN 250-XXXXXXXXC 250 XXXD

While in the opposite direction the regular dialog:

250-ENHANCEDSTATUSCODES 250-PIPELINING 250-8BITMIME 250-SIZE 250-DSN 250-ETRN 250-AUTH GSSAPI DIGEST-MD5 CRAM-MD5 250-DELIVERBY 250 HELP

Becomes mutated into:

250-ENHANCEDSTATUSCODES 250-PIPELINING 250-8BITMIME 250-SIZE 250-DSN 250-ETRN 250-AUTH GSSAPI DIGEST-MD5 CRAM-MD5 250-XXXXXXXXA 250 XXXB

What is going on here?

Suggestions?

-Ramon

Reply to
Ramon F Herrera
Loading thread data ...

Turn off SMTP 'fixup' on your misdesigned firewall.

Cisco does stupid stuff to SMTP. They cannot be trusted to handle your mail, as they have years of track record showing that they do not understand the protocol and have spent years telling their unfortunate customers that what they do is some sort of fix. They have lied to you.

Consult your documentation or call Cisco to ask how to solve your problem. It is NOT a Sendmail issue.

Reply to
Bill Cole

It has been known for years that the *fixup protocol smtp' command in fact means fu**up protocol smtp

Switching that option off is among the first things to do when configuring a PIX.

Wolfgang

Reply to
Wolfgang Kueter

Yep, Shisco happens.

Reply to
NPG

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.