Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations biv343 on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

How to define local (inside) network

Status
Not open for further replies.

rhyno2k

IS-IT--Management
Jun 9, 2001
222
US
Hi,


I just purchased a PIX 501 to secure a small corporate network. I have it connected to our Cisco 1600 router on the external side and to our Cisco catalyst switch (along with all other servers & workstations) on the inside. Functionally it works fine.

However, I am having lots of trouble sending mail. Getting lots of bouncebacks to the tune of:

"Your message did not reach some or all of the intended recipients.

The following recipient(s) could not be reached:

'somebody@outside.com' on 2/2/2004 2:27 PM
550 Relaying denied for <somebody@outside.com>&quot;

We generally use a W2K Server as a NAT server, which also contains our email package. So the e-mail clients are configured to use &quot;mail.mycompany.com&quot;, it recognizes it as internal, and all is well.

However, with the PIX, it looks like my request is going outside the PIX, looking back externally for &quot;mail.mycompany.com&quot;, and my mail server thinks it's trying to be used as a relay, and denies the request.

How can I tell the PIX that all 10.0.0.x addresses (our internal subnet) are AOK, and to use LOCAL dns to resolve &quot;mail.mycompany.com&quot;?

The documentation that comes with the PIX is awful. Shows you how to physically connect it -- that's about it. Have found a few helpful web sites, but still need a good &quot;How-To&quot; guide with practical examples. Any web sites to this effect would be appreciated as well!


Thanks!
 
Hi rhyno,

Check my post above &quot;VPN Client Setup&quot;, I posted a PIX501 config everything works fine except the VPN. Why don't you setup NAT on the PIX501 instead of Win2000.

I hope this helps.

Alex.
 
some commands to search on the cisco site are:
global, NAT, Static, Access-list,and Access-group
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top