Setting up a ASA 5510 cannot get SMTP to come in

I have a ASA 5510 (ver 8.4) and I have been all over the support sites looking for what I am doing wrong. I have a sanitized cut n paste of the OBJECT, NAT, ACCESS-LIST and Packet Tracer output and it keeps failing on the NAT with a rpf-check. Once i get the SMTP flowing I have to open up HTTP and HTTPS to one of the servers also.
Any help greatly appreciated!!!
Here it is:
RVGW# sh run object
object network WiFi
subnet 172.17.100.0 255.255.255.0
description WiFi
object network inside-net
subnet 172.17.1.0 255.255.255.0
object network NOSPAM
host 172.17.1.49
object network BH2
host 172.17.1.60
RVGW# sh run nat
object network inside-net
nat (Inside,Outside) dynamic interface
object network NOSPAM
nat (Inside,Outside) static 5.29.79.12
object network BH2
nat (Inside,Outside) static 5.29.79.11 service tcp smtp smtp
RVGW# sh access-list
access-list cached ACL log flows: total 0, denied 0 (deny-flow-max 4096)
            alert-interval 300
access-list Outside_access_in; 2 elements; name hash: 0xe796c137
access-list Outside_access_in line 1 extended permit tcp any object NOSPAM eq sm                                     tp 0x49e8de7d
  access-list Outside_access_in line 1 extended permit tcp any host 172.17.1.49                                      eq smtp (hitcnt=3) 0x49e8de7d
access-list Outside_access_in line 2 extended permit tcp any object BH2 eq smtp                                      0xddf3d54c
  access-list Outside_access_in line 2 extended permit tcp any host 172.17.1.60                                      eq smtp (hitcnt=2) 0xddf3d54c
RVGW# packet-tracer input outside tcp 4.2.2.2 25 172.17.1.49 25
Phase: 1
Type: ROUTE-LOOKUP
Subtype: input
Result: ALLOW
Config:
Additional Information:
in   172.17.1.0      255.255.255.0   Inside
Phase: 2
Type: ACCESS-LIST
Subtype: log
Result: ALLOW
Config:
access-group Outside_access_in in interface Outside
access-list Outside_access_in extended permit tcp any object NOSPAM eq smtp
Additional Information:
Phase: 3
Type: IP-OPTIONS
Subtype:
Result: ALLOW
Config:
Additional Information:
Phase: 4
Type: INSPECT
Subtype: inspect-smtp
Result: ALLOW
Config:
class-map inspection_default
match default-inspection-traffic
policy-map global_policy
class inspection_default
  inspect esmtp _default_esmtp_map
service-policy global_policy global
Additional Information:
Phase: 5
Type: NAT
Subtype: rpf-check
Result: DROP
Config:
object network NOSPAM
nat (Inside,Outside) static 5.29.79.12
Additional Information:
Result:
input-interface: Outside
input-status: up
input-line-status: up
output-interface: Inside
output-status: up
output-line-status: up
Action: drop
Drop-reason: (acl-drop) Flow is denied by configured rule
RVGW#

hi
Please use the public IP (5.29.79.12) in packet tracer command as a destination , not the private 172.17.1.49
regards,
Mohammad

Similar Messages

  • Cannot get smtp online, all info for email provider correct

    I cannot get SMTP online on a POP email accout. All settings confirmed with email provider....any ideas?

    Hello,
    Who is your eMail provider, the part after the @ sign?
    In Mail's Window Menu, choose Connection Doctor, any red dots for status, if so what is the message?
    Then click the Show Details button & Check again.

  • My ipad is disabled and I cannot restore it because the Function Find My Ipad setting was on, and I cannot get in the ipad to turn off the setting in order to restore the ipad. Does anyone know how to solve the problem

    My ipad is disabled and I cannot restore it because the Function Find My Ipad setting was on, and I cannot get in the ipad to turn off the setting in order to restore the ipad. Does anyone know how to solve the problem

    Force iPad into Recovery Mode. Follow step 1 to 5 very closely.
    http://support.apple.com/kb/HT1808
    Note: You may have to repeat the above a few times.

  • Icloud was originally set up wrong and I cannot get in to change my settings and no longer know the password

    icloud was originally set up wrong and I cannot get in to change my settings and no longer know the password

    Go to http://appleid.apple.com and click 'Forgot password'. Enter the ID you set iCloud up with. A new password will be sent to your associated email address.

  • Ihave downloaded iCloud to my new PC and am using windows 7 and office 2010. I cannot get iCloud to come up on Outlook with the choices for CalendCar and contacrts, my iMail account is there, but not the general coud choices. What am I doing wrong.

    I have downloaded iCloud to my new PC and am using Windows 7 and Offie 2010. I cannot get iCloud to come up on Outlook with the choices for Calendar and Contacts, my iMail accnt is there***.me.com, but not the general Cloud choices for calendar and contacts? What am I doing wrong?

    I have I cloud 2.0.2.187 loaded just downloaded yesterday.

  • I dropped my iPad and the screen went blank.  I cannot get it to come back on.

    I dropped my ipad and the screen went blank.  I cannot get it to come back on.

    Try a reboot by holding both the power and home buttons until the apple logo appears, ignore the red slider if that appears.  If that does not work you need to take the iPad to an Apple store genius bar to have it evaluated by the technicians.

  • My Firefox crashed and I cannot get it to come back up. I have a MAC. What now?

    My Firefox crashed. I had been cleaning out some downloads and I don't know if that had anything to do with it but now I cannot get it to come back up. Help.

    Create a new profile as a test to check if your current profile is causing the problems.
    See "Basic Troubleshooting: Make a new profile":
    * https://support.mozilla.com/kb/Basic+Troubleshooting#w_8-make-a-new-profile
    There may be extensions and plugins installed by default in a new profile, so check that in "Tools > Add-ons > Extensions & Plugins" in case there are still problems.
    If that new profile works then you can transfer some files from the old profile to that new profile, but be careful not to copy corrupted files.
    See:
    * http://kb.mozillazine.org/Transferring_data_to_a_new_profile_-_Firefox
    See:
    * http://kb.mozillazine.org/Firefox_crashes
    * https://support.mozilla.com/kb/Firefox+crashes
    * https://support.mozilla.com/en-US/kb/latest-firefox-issues
    If you have submitted Breakpad crash reports then post the IDs of one or more Breakpad crash reports (bp-xxxxxxxx-xxxxxxxxx-xxxx-xxxxxxxxxxxx). You can find the IDs of the submitted crash reports on the about:crashes page. You can open the about:crashes page via the location bar, like you open a website.
    See:
    * http://kb.mozillazine.org/Breakpad (Mozilla Crash Reporter)
    * https://support.mozilla.com/kb/Mozilla+Crash+Reporter
    * https://developer.mozilla.org/en/How_to_get_a_stacktrace_for_a_bug_report

  • ASA 5510 cannot connect to Microsoft IAS

    I'm at a total loss here. I am transitioning from a Microsoft ISA server to a Cisco ASA 5510. So far so good, until it comes to getting AAA functioning properly. I have a Microsoft IAS server that is functioning properly, however when I try to test it through the ASA's ASDM it errors out. When I run a packet trace it shows it's being blocked by the dreaded implicit ACL. The funny thing is that I can ping and traceroute to the IAS server from the ASA. I found numerous config examples for AAA using IAS, but still not working.
    Could it possibly be behaving this way because my ASA and my IAS server are on two different internal netowrks? (172.31.1.x-ASA, 10.1.1.x-IAS)
    Any help would be greatly appreciated!!

    Ohh no no, That is going to work, anything placed from the ASA firewall itself will work cuz it does not have anything that would limit the Control plane.
    Now, would you care to share the packet tracer (without the detail command please), remove the addresses and what no to see at which point does it fail?
    The security level of the IAS, what is it?
    Mike

  • I cannot get firefox to come up.

    I have used firefox for a long time. NowI cannot get on the web at all the since last night. 7/09/11. What is going on?

    There could be several reasons why Firefox does not even start up. Check if the possible solutions given in this article help: [[Firefox will not start]].

  • Our primary Thunderbird account is working, but the staff who have access via wi fi cannot get it to come up.

    Our main office computer's email is working fine, but staff members who access their separate accounts by wi fi can't get Thunderbird to come up. They can, however, access their non-Thunderbird email accounts, so the wifi isn't the problem.

    "can't get Thunderbird to come up" - please describe further what you mean by this.
    Similarly, "They can, however, access their non-Thunderbird email accounts" doesn't make any immediate sense to me. Can you indicate what it is they are doing that does work?
    There's no such thing as a "Thunderbird email account". Most people using this phrase seem to use it to describe an email account provided by their ISP, which they access via an email client such as Thunderbird as opposed to accounts provided by independent providers such as googlemail, yahoo, outlook.com, etc. However I can't infer your intended meaning here.

  • Entered incorrect email address when setting up Apple ID, therefore cannot get verification email. Also 'redeemed' $50 iTunes card before mistake was realised.

    Entered incorrect email address when setting up Apple ID, also 'redeemed' $50 iTunes card before mistake was realised. Naturally, the email address cannot be validated, so cannot proceed further. Please help.

    You can't merge IDs, but if you want to change the ID:
    For iMessage, go to Settings>Messages>Send & Receive, tap the ID sign out, sign back in using the new ID.
    For FaceTime, do the same thing in Settings>FaceTime.
    For Purchasing, do this in Settings>iTunes & App Store.
    For iCloud, start by saving your photo stream photos to your camera roll by opening your My Photo Stream album, tap Select, tap all the photos you want to save, tap the share icon (box with upward pointing arrow), then tap Save to Camera Roll. Then go to Settings>iCloud, tap Delete Account and provide the password and choose Keep on My iPhone when prompted, then sign back in with your new ID and choose Merge to upload your data.

  • Cannot get SMTP to work, Please Help.

    Hello,
    I recently bought the WVC80N camera.
    The main reason i purchased it was to have motion alerts emailed to me.
    I have been trying all different combination for a week and still get TEST EMAIL FAILED.
    Here are my specifics:
    ISP: Verizon FiOS
    I have a D-link N router setup as an access point that connects to my FiOS router/modem.
    The camera connectes to the wireless on the D-Link router.
    I have tried my ISP SMTP settings,
    I have Verizon email through Yahoo! so I also tried those settings.
    I made a GMX account and tried that, all with no luck.
    Can someone please provide me some insight on how to get this working?
    Thank You!
    Solved!
    Go to Solution.

    For the camera to send you do NOT need to open ports, the camera is sending SMTP OUTBOUND, opening ports is for INBOUND traffic.
    So, the issue lies within Verizon and not with Cisco, it's the way you are sending out and that verizon is blocking SMTP outbound unless the FROM address matches the Verizon domain and you are an authorized user with a valid email on there.
    They may also have SMTP port 25 outbound BLOCKED, so you'd have to use an alternate port. Not sure since I don't have verizon.  BUT, there is a solution with something like the TZO OMR service, which is outbound mail relay, allowing your camera to send through the TZO Servers and not Verizon. TZO accepts mail on port 2525 also, which allows you to get around the blocked port 25 from Verizon.
    It's not cisco's fault, be mad at your ISP for locking crap down....not cisco
    http://www.MyHomeServer.com
    Linksys IP camera reviews, Tutorials and How-To's on Web & Mobile Streaming

  • I cannot get Firefox to come up--it tells me that it is unable to load.

    I have been trying to get on Firefox for several days now, and it always gives me error messages that state:
    Unable to connect --
    Firefox can't establish a connection to the server at home.mysearch.com
    Please help!

    The Firefox Home app for iOS is not the Firefox browser but rather for to synce with your desktop Firefox to have your Firefox desktop history, bookmarks and open tabs on your iPhone/iPad.
    http://www.mozilla.org/en-US/mobile/home/
    http://www.mozilla.org/en-US/mobile/home/faq/
    https://wiki.mozilla.org/Mobile/Platforms#Other_Platforms
    iPhone/iPad/iPod
    We have no plans to release the full Firefox browser for iOS. The iOS SDK agreement requires apps to use Apple's own JavaScript engine (or none at all, like Opera Mini which downloads pre-rendered pages from Opera's servers and cannot run JavaScript code in the client). Because of this, we have no supported way to distribute Firefox's rendering and JavaScript engine to iPhone users.

  • I cannot get Firefox to come up on my iPad at all. It is synced and I am registered but I do not know how to get it to work

    I have the Mozilla icon but when I tap it it is just how to use Firefox home. I want Firefox as my browser and have safari and can't get Mozilla up

    The Firefox Home app for iOS is not the Firefox browser but rather for to synce with your desktop Firefox to have your Firefox desktop history, bookmarks and open tabs on your iPhone/iPad.
    http://www.mozilla.org/en-US/mobile/home/
    http://www.mozilla.org/en-US/mobile/home/faq/
    https://wiki.mozilla.org/Mobile/Platforms#Other_Platforms
    iPhone/iPad/iPod
    We have no plans to release the full Firefox browser for iOS. The iOS SDK agreement requires apps to use Apple's own JavaScript engine (or none at all, like Opera Mini which downloads pre-rendered pages from Opera's servers and cannot run JavaScript code in the client). Because of this, we have no supported way to distribute Firefox's rendering and JavaScript engine to iPhone users.

  • Husband just purchased IPAD and I cannot connect to the internet.  I found a network that appears to be "useable" but I cannot get anything to come up on the screen;(

    I just got my ipad yesterday, and already I have a prob;(  When I look for a network, I find one that appears to be appropriate, but I am not able to connect to the internet;(  I have a Netgear router, but the real deal is...(being blatantly honest here becuz I desparately want to use my new DEVICE!!)  I don't know what exactly to do with the router to get a connection w/my ipad.  At this point it is just simply turned on...meaning the adapter is hooked up....that's where I'm at and if anyone know any info plz plz...help.  I am currently using my desktop to write this....just fyi
    Thank you
    Gail

    You only connect automatically once the device knows and remembers the connection. You will need the Password to connect to it for the very first time.
    Clearly the Laptop was setup with the correct password 5 years ago.
    The only thing that can be suggested is to look on the side of the Netgear router, sometimes the default password is printed there.
    If that doesn't work, there's not much to do other than contacting your ISP, and have them walk you through resetting the router so it goes back to the default password and settings.

Maybe you are looking for

  • Error while executing webdynpro application : he URL does not contain full

    Dear All, I had installed SAP in my system.But when I am testing webdynpro application I am getting the belwo error. Please let me knwo what setting I need to do to avoid this error. Error when processing your request What has happened? The URL http:

  • Screen-field value not visible

    Hi All , I have added couple of fields to the standard transaction .Used  a badi to achieve that.Now am able to send the values from one of the methods in the same badi to the custom field and a standard table is getting updated (which was created wi

  • SMTP server error message

    My scan to email feature has suddenly quit working.  When I try to scan a document, the scan feature trys to connect to smtp.aol.com, as it always has.  After approximately 5 seconds, I receive the following error message:  "Cannot resolve the SMTP s

  • Re: (forte-users) Round-trip database design

    We have used Erwin quite sucessfully, but it's not cheap. "Rottier, Pascal" <Rottier.Pascalpmintl.ch> on 02/15/2001 04:51:01 AM To: 'Forte Users' <forte-userslists.xpedior.com> cc: Subject: (forte-users) Round-trip database design Hi, Maybe not 100%

  • Some videos & streaming sites not working pink background

    youtube and most sites work fine but the odd few dont here is what i see using xp flashplayer upto date tried turning off addblock nothing happend any ideas? any help will be appreciated