Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Pix firewall kills outlook 2

Status
Not open for further replies.

rouse01

IS-IT--Management
Sep 10, 2001
143
US
I'd been using a 1720 with port forwarding/Access control lists to move mail on my inhouse email server. My outlook clients were setup to use mail.domain.net for incoming & outgoing mail. This worked fine for my work station and roaming laptop users until the cisco pix firewall was installed.

Now the Outlook clients inside the network won't resolve to the mail.domain.net, but instead need the (class c) ip address entered in the pop3 & smtp fields. The CE told me that the pix won't allow traffic that originates from inside to 'hairpin' back to an inside address.

We aren't a large office, so I can modify the hosts file on the workstations to resolve the dot addr to the domain addr. But this won't work on my laptops, because they'll have to change their hosts or outlook config depending on if they are inside my network or on the road.

Does this sound right?

Thanks - Keith
 
I'm not sure I can fully visalise this but can you confirm where the DNS server is that is resolving your mail domain name, i.e. is it on the inside or outside of the PIX?
 
You cant Redirect traffic down the same interface on a PIX, if this is what you mean.

As KiscoKid is implying this can be fixed with DNS. You need your inside DNS server to resolve for mail.domain.net to the internal IP address of your email server, and the outside DNS server to resolve to the public IP address. If you dont have an internal DNS Server I beleive you can use the Alias command, and low and behold it has been replace by DNS Doctoring:

Hope that is of some help

UnaBomber
ccnp mcse2k
 
Thanks both. I do not have an internal dns server, so the alias command worked! I printed off the tech_note, showed it to the engineer and all is good.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top