I've got a PIX 506 that seems to be having trouble allowing SSL email (ports995 and 465) through. It DOES send eventually, but I had to crank the timeouts up to 3 minutes in Outlook.
Now, I thought I opened everything that I would need on the PIX, and like I said, it IS working.....just extremely slow. Receive is immediate, Send is delayed.
Has anyone ever seen this? The 506 is running 6.3(5). Below is the relevant part of the config. Am I missing something? Thanks, Mike.
fixup protocol smtp 25 fixup protocol sqlnet 1521 fixup protocol tftp 69 names object-group service SSL_email tcp description So that SSL mail sends and receives port-object range 995 996 port-object range 465 466 object-group network Mailserver network-object 69.X.X.X 255.255.255.255 access-list mail_send_out remark Let mail server in to send messages access-list mail_send_out permit tcp any object-group Mailserver object-group SSL_email access-list mail_send_out permit tcp any any eq 465 access-list mail_send_out permit tcp any any eq 995 access-group mail_send_out in interface outside