Exchange Server Forums
Forums |
Register |
Login |
My Profile |
Inbox |
RSS
|
My Subscription |
My Forums |
Address Book |
Member List |
Search |
FAQ |
Ticket List |
Log Out
Can't receive email (exchange server behind firewall)
Users viewing this topic:
none
|
Logged in as: Guest
|
Login | |
|
Can't receive email (exchange server behind firewall) - 27.Jul.2010 5:29:13 AM
|
|
|
bayoeharyanto
Posts: 3
Joined: 27.Jul.2010
Status: offline
|
I have managed to build a mail server with exchange 2010. configuration that I use is still the default. to send mail has been successful, but still can not receive email. as info, when I put on the exchange server in local network with other workstations, the local IP 10.80.136.202. And public IP 202.171.x.x We also have a Firewall ASA 5505, with a configuration like this: ------- asa-ujam# sh run : Saved : ASA Version 8.2(1) ! hostname asa-ujam enable password xxxxxxxxxxxxxxxxxx encrypted passwd xxxxxxxxxxxxxxxxx encrypted names ! interface Vlan1 nameif inside security-level 100 ip address 10.80.136.5 255.255.255.0 ! interface Vlan2 nameif outside security-level 0 ip address 202.171.x.x 255.255.255.240 ! interface Ethernet0/0 switchport access vlan 2 ! interface Ethernet0/1 shutdown ! interface Ethernet0/2 ! interface Ethernet0/3 ! interface Ethernet0/4 ! interface Ethernet0/5 ! interface Ethernet0/6 ! interface Ethernet0/7 ! ftp mode passive clock timezone ICT 7 dns domain-lookup inside dns domain-lookup outside object-group service inbound-tcp service-object tcp eq domain service-object tcp eq https service-object tcp eq smtp service-object tcp eq ssh access-list ujam-split standard permit 10.80.136.0 255.255.255.0 access-list ujam-jkt_splitTunnelAcl standard permit 10.80.136.0 255.255.255.0 access-list inside_nat0_outbound extended permit ip 10.80.136.0 255.255.255.0 10.80.139.0 255.255.255.240 access-list inside_nat0_outbound extended permit ip any 10.80.139.0 255.255.255.240 access-list ujam-vpn_splitTunnelAcl standard permit 10.80.136.0 255.255.255.0 access-list outside_access_in extended permit tcp any host 202.171.x.x eq https access-list outside_access_in extended permit tcp any host 202.171.x.x eq www access-list outside_access_in extended permit tcp any host 202.171.x.x eq smtp pager lines 24 logging enable logging asdm informational mtu inside 1500 mtu outside 1500 ip local pool vpnpool 10.80.139.1-10.80.139.15 mask 255.255.255.240 icmp unreachable rate-limit 1 burst-size 1 asdm image disk0:/asdm-621.bin no asdm history enable arp timeout 14400 global (outside) 1 interface nat (inside) 0 access-list inside_nat0_outbound nat (inside) 1 0.0.0.0 0.0.0.0 access-group outside_access_in in interface outside route outside 0.0.0.0 0.0.0.0 202.171.x.1 1 timeout xlate 3:00:00 timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00 timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00 timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute timeout tcp-proxy-reassembly 0:01:00 dynamic-access-policy-record DfltAccessPolicy aaa authentication telnet console LOCAL aaa authentication ssh console LOCAL aaa authentication http console LOCAL http server enable http 192.168.1.0 255.255.255.0 inside http 0.0.0.0 0.0.0.0 outside http 10.80.136.0 255.255.255.0 inside no snmp-server location no snmp-server contact snmp-server enable traps snmp authentication linkup linkdown coldstart crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac crypto ipsec security-association lifetime seconds 28800 crypto ipsec security-association lifetime kilobytes 4608000 crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set pfs group1 crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP -AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5 crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP crypto map outside_map interface outside crypto isakmp enable outside crypto isakmp policy 10 authentication pre-share encryption 3des hash sha group 2 lifetime 86400 telnet 10.80.136.0 255.255.255.0 inside telnet timeout 5 ssh scopy enable ssh 0.0.0.0 0.0.0.0 outside ssh timeout 5 console timeout 0 ! ! prompt hostname context Cryptochecksum:ef075899f6cddb087552a62e1de4cd17 : end asa-ujam# ------- Please help how to exchange server can successfully receive mail from the Internet? How to setup on the ASA firewall should be? Thanks
|
|
|
RE: Can't receive email (exchange server behind firewall) - 27.Jul.2010 10:46:26 AM
|
|
|
Marc.dekeyser
Posts: 225
Joined: 19.Apr.2010
Status: offline
|
Dit you forward port 25 to the exchange?
_____________________________
* No rights or priviliges can be taken from my posts. * Always make a backup! * http://kb.geminon.be
|
|
|
RE: Can't receive email (exchange server behind firewall) - 27.Jul.2010 9:27:52 PM
|
|
|
markmorow
Posts: 68
Joined: 6.Nov.2009
Status: offline
|
You'll also need to create a receive connector for external mail.
_____________________________
Mark Morowczynski|MCT| MCSE 2003:Messaging, Security|MCITP:ES, SA,EA|MCTS:Windows Mobile Admin|Security+|http://almostdailytech.com
|
|
|
RE: Can't receive email (exchange server behind firewall) - 29.Jul.2010 2:19:51 AM
|
|
|
bayoeharyanto
Posts: 3
Joined: 27.Jul.2010
Status: offline
|
How I do it?
|
|
|
RE: Can't receive email (exchange server behind firewall) - 29.Jul.2010 2:27:51 AM
|
|
|
bayoeharyanto
Posts: 3
Joined: 27.Jul.2010
Status: offline
|
Can use an existing default receive connector?
|
|
|
RE: Can't receive email (exchange server behind firewall) - 23.Aug.2010 6:57:21 AM
|
|
|
jeyaramrajes
Posts: 15
Joined: 20.Apr.2010
Status: offline
|
On the Default Receive connector Properties, Select the permission tab and check the Anonymous Users. This will allow the Exchang 2007 organization to receive the mails from Internet.
_____________________________
Rajeswaran Jeyaraman Chennai, Tamilnadu, India
|
|
|
New Messages |
No New Messages |
Hot Topic w/ New Messages |
Hot Topic w/o New Messages |
Locked w/ New Messages |
Locked w/o New Messages |
|
Post New Thread
Reply to Message
Post New Poll
Submit Vote
Delete My Own Post
Delete My Own Thread
Rate Posts |
|