What works for me is the following.

Enable guards
No fixup protocol SMTP 25
Conduit permit tcp host x.x.x.x eq smtp any

In Imail I have SMTP security set to relay for 127.0.0.1 only and then I
use SMTP Auth because all of are agents are on another network that we
do not support and I have no way of knowing there IPs. Don't ask the
travel industry is verrrry different. Seems to work.

~Paul~

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of David Sullivan
Sent: Monday, May 06, 2002 11:39 AM
To: [EMAIL PROTECTED]
Subject: [IMail Forum] SMTP Commands

Hi,

We're installing a Cisco Pix firewall with "MailGuard" feature that is
suppose to clean-up and filter SMTP commands.  I am trying to verify
that
limiting SMTP to these commands will not affect our Imail Server.  I
called
Ipswitch tech support and they said it was OK but she didn't sound to
sure
about her answer.  Can anyone here give me some feedback?

Here is the description of the feature:

"These seven minimum-required commands are: HELO, MAIL, RCPT, DATA,
RSET,
NOOP, and QUIT. Other commands, such as KILL, WIZ, and so forth, are
intercepted by the PIX and they are never sent to the mail server on the
inside of your network. The PIX responds with an "OK" to even denied
commands, so attackers would not know that their attempts are being
thwarted."

Thanks

David


Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Please visit the Knowledge Base for answers to frequently asked
questions:  http://www.ipswitch.com/support/IMail/
---
[This E-mail scanned for viruses by Declude Virus/McAfee]


---
[This E-mail scanned for viruses by Declude Virus/McAfee]


Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Please visit the Knowledge Base for answers to frequently asked
questions:  http://www.ipswitch.com/support/IMail/

Reply via email to