Security Basics mailing list archives

Re: Cisco PIX fixup protocol command


From: "James Turnbull" <james () lovedthanlost net>
Date: Fri, 13 Feb 2004 10:58:58 +1100

Chris Curtiss wrote:
FWIW, I have experienced problems with fixup SMTP, using a Postfix
relay behind a PIX 515e.

There was a bug, reported fixed over a year ago by Cisco, relating to
interoperability with Postfix, but I was still unable to make it play
with a large set of inbound mail.  We ended up having to turn it off
and letting Postfix do its thing.

The only opion offered by a Cisco consultant I know was "What's a
Postfix, use Sendmail".

We did some extensive testing on the PIX fixup commands and SMTP and found
the following MTAs have issues with EHLO and ESMTP:

Qmail
Postfix
Courier
Exchange 2000/2003 (but not 5.5)

Very annoying because it took us some time to determine exactly where the
problem was.

Regards

James Turnbull


---------------------------------------------------------------------------
Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection

Protect your network with the comprehensive security solution that
integrates six applications for ease of use and lower TCO.

Firewall - Virus protection - Spam protection - URL blocking - VPN
- Wireless security.

Download 30-day evaluation at:
http://www.astaro.com/php/contact/securityfocus.php
----------------------------------------------------------------------------


Current thread: