nanog mailing list archives

Re: disabling SMTP


From: Rob Nelson <ronelson () vt edu>
Date: Mon, 29 Mar 2004 07:20:47 -0500



when smtp fixup is on (default on many older pixes, i gather that there
may be some improvements on newer pixes), the smtp banner
is mostly obscured by * characters. the intent is a classic security
by obscurity play, to hide the type and verison of the MTA behind
the pix.

Okay, so this is a problem when an SMTP server is hosted behind the PIX? I thought the fixup statements were for outbound connections, and with it on right now I get the full banner from SMTP servers. I don't host an SMTP server myself, so can't check that.

Rob Nelson
ronelson () vt edu


Current thread: