Pix501: allow all incoming smtp to one host and all smtp out from one host only

I have a pix501 and I have a mail server. What I would like to do is ensure that smtp traffic from the web only goes to my mail server and that my mail server is the only machine on my local network that can send to the internet on port 25. This is to secure the possibility of bots on my childrens PCs spamming other users. The mail server has been relay secured for selected PCs only.
To the pix501; I think the following is what I need, but would like somebody to confirm or correct me:
interface ethernet0 auto
interface ethernet1 100full
nameif ethernet0 outside security0
nameif ethernet1 inside security100
access-list inbound permit tcp any host x.x.x.x eq smtp
access-list outbound permit tcp host x.x.x.x ant eq smtp
access-group inbound in interface outside
access-group outbound in interface inside
Most important:
1. Have I got the access-lists right? Does pix501 support host x.x.x.x (ip of local webserver 192.168.x.x)
2. Are the access lists the right way around?
3. Is the access-group setup right?
4. Is there anything else that needs doing/
Any help appreciated.
Note: I am a Cisco newbie and trying to learn,

Thanks for that information.
I thought about this some more, after seeing your response, and I was wondering; if I only want to restrict smtp outbound traffic, but allow all other traffic, would the following work, as I dont have to allow each specific port/ip address:
access-list outbound permit tcp host 192.168.1.3 any eq smtp
access-list outbound permit tcp host 192.168.1.36 any eq smtp
access-list outbound deny tcp any any eq smtp
access-list outbound permit udp any any
access-list outbound permit tcp any any
I realise that this would open all sorts of other security risks, but at least trojans/worms will not be able to spam from PCs other than those listed as per the first 2 lines ( which is my major concern at the moment). As I learn more about the traffic on my network I can block more undesirable ports.
Sorry to be a pain, but this could be useful to other and the more complete the setup, the easier it will be for them.

Similar Messages

Maybe you are looking for

  • DBD: parse error unexpected " found.

    Hi, Login to Universe Designer by SAP account, and during editing a connection, we tried to select the auth mode as "Use Single Sign-On when view and ...." , then next, got the following error message in a popup dialog:    DBD: parse error unexpected

  • I have a .band file on my desktop and i can't get rid of it

    I can't delete it, move it or get info on it. What do I do?

  • C++ Program crashes at OCIDateFromText (8.1.7)

    Environment: DB Server: Oracle 8.1.6 DB Client: Oracle 8.1.7 on Sun Solaris 8 Compiler: g++ Mode: Multi-Threading (pthread) Architecture of the program: 10 threads for DB Access. I create 1 DB Environment for per thread with mode OCI_THREADED|OCI_OBJ

  • OBIEE 11G OEL5.5 app deployments like analytics, bipublisher not starting.

    Ok, I successfully installed OBIEE 11.1.1.3.0 on OEL 5.5 without any errors. I was also able to log on to 1) http://myhostname:7001/console 2) http://myhostname:7001/em 3) http://myhostname:9704/analytics I did not notice any errors, everything was r

  • Sales Rep. Modelling for Query.

    As you might know, in SD one can have 4 Sales Rep for the same document (i.e. Sales Order). All of them goes to different fields in the extractors and from there, up to the DSO/Cubes. How can I model them if I have to write a query of Sales by Sales