I've got a 515R firewall which is allowing access out no problem for users on the internal LAN, but when I try to direct mail and web flow through it to our mail server, the translation just doesn't seem to work - I've followed pretty closely - my config (ip's changed) is below:
Any help really appreciated - I need to go to bed!
: Saved
: Written by enable_15 at 14:07:59.632 UTC Sat Jul 6 2002
PIX Version 6.2(2)
nameif ethernet0 outside security0
nameif ethernet1 inside security100
enable password 2Av431E9tdni5Rtb encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
hostname pix
domain-name abc.com
fixup protocol ftp 21
fixup protocol http 80
fixup protocol ils 389
fixup protocol rsh 514
fixup protocol rtsp 554
fixup protocol smtp 25
fixup protocol sip 5060
fixup protocol skinny 2000
no fixup protocol sqlnet 1521
no fixup protocol h323 ras 1718-1719
no fixup protocol h323 h225 1720
fixup protocol domain 53
no names
access-list 100 permit icmp any any echo-reply
access-list 100 permit icmp any any time-exceeded
access-list 100 permit icmp any any unreachable
access-list 100 permit tcp any host 213.24.142.2 eq smtp
access-list 100 permit tcp any host 213.24.142.2 eq www
access-list 100 permit tcp any host 213.24.142.2 eq https
pager lines 24
logging on
logging timestamp
access-group 100 in interface outside
conduit permit icmp any any
route outside 0.0.0.0 0.0.0.0 213.24.142.1 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 si
p 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server RADIUS protocol radius
aaa-server LOCAL protocol local
no snmp-server location
no snmp-server contact
snmp-server community public
no snmp-server enable traps
floodguard enable
no sysopt route dnat
telnet timeout 5
ssh timeout 5
terminal width 80
Cryptochecksum:51214826cacf7d96032ae5a941da095f
Any help really appreciated - I need to go to bed!
: Saved
: Written by enable_15 at 14:07:59.632 UTC Sat Jul 6 2002
PIX Version 6.2(2)
nameif ethernet0 outside security0
nameif ethernet1 inside security100
enable password 2Av431E9tdni5Rtb encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
hostname pix
domain-name abc.com
fixup protocol ftp 21
fixup protocol http 80
fixup protocol ils 389
fixup protocol rsh 514
fixup protocol rtsp 554
fixup protocol smtp 25
fixup protocol sip 5060
fixup protocol skinny 2000
no fixup protocol sqlnet 1521
no fixup protocol h323 ras 1718-1719
no fixup protocol h323 h225 1720
fixup protocol domain 53
no names
access-list 100 permit icmp any any echo-reply
access-list 100 permit icmp any any time-exceeded
access-list 100 permit icmp any any unreachable
access-list 100 permit tcp any host 213.24.142.2 eq smtp
access-list 100 permit tcp any host 213.24.142.2 eq www
access-list 100 permit tcp any host 213.24.142.2 eq https
pager lines 24
logging on
logging timestamp
access-group 100 in interface outside
conduit permit icmp any any
route outside 0.0.0.0 0.0.0.0 213.24.142.1 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 si
p 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server RADIUS protocol radius
aaa-server LOCAL protocol local
no snmp-server location
no snmp-server contact
snmp-server community public
no snmp-server enable traps
floodguard enable
no sysopt route dnat
telnet timeout 5
ssh timeout 5
terminal width 80
Cryptochecksum:51214826cacf7d96032ae5a941da095f