[Raw Msg Headers][Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Cisco PIX and ESMTP-ORCPT breakage



mea@nic.funet.fi wrote:
> Some news via Cisco's Finland office regarding breaking of ESMTP
> handling in current cisco PIX software releases while using
> so called MailGuard facility:
> 
> MailGuard ESMTP bugfix will be in
> 
>       version 4.1.6; release around 1st of May, 1998
>       version 4.2.1; release around 15th of May, 1998
> 
> I shall be most interested to see, HOW they fixed it...
> 
> /Matti Aarnio <mea@nic.funet.fi>

I'm not on the PIX team, but I've been told that the above versions will
respond to EHLO with a 550 response code, and verified that a 4.2 system
does have this behavior.

4.2 also sends an SMTP welcome banner to "220 SMTP/cmap Ready" as well,
in an attempt to get mailers that look for "ESMTP" in the welcome banner
to not send an initial EHLO.  I don't know if 4.1.6 also does this.

I know this isn't the best solution, and that it eliminates all SMTP
service extensions.  I encourage Ned to add this behavior to
draft-freed-firewall-req-02.txt.

-Dan Wing