内网访问自己内网邮件服务器问题,CISCO高手进

发布时间:2024-05-15 00:52 发布:上海旅游网

问题描述:

先说下我这边网络环境,2M专线接入到一台CISCO ASA5510防火墙,防火墙也当路由器用,内网一台邮件服务器,用WINMAIL架设的系统,IP为192.168.0.251。这台邮件服务器是做企业邮箱用的,并申请了域名,假设为mail.xxxxxx.cn。
现在在外网访问域名mail.xxxxxx.cn是正常的,可以看到WINMAIL的WEB页面的,外网也可以填mail.xxxxxx.cn来做为OE和OUTLOOK里的stmp和pop3服务器地址

内网却不能输mail.xxxxxx.cn访问,OE和OUTLOOK里也不能用mail.xxxxxx.cn来作为smtp和pop3服务器,只能填内网地址192.168.0.251才可以正常收发

问题是公司有员工是用自己的笔记本办公的,如果给他填内网地址,那么他回家就收发不了邮件了。

我尝试过在内网的域控制器上配置DNS,添加一条A纪录 192。168。0。251到mail.xxxxxx.cn,可是有的机器还是不行,有的可以。

目前mail.xxxxxx.cn这个域名没做反向解析,有可能和这个有关吗?

CISCO 5510防火墙是请专业人员配置映射和NAT的,现将配置贴出来如下:

access-list 120 extended permit ip any 192.168.0.0 255.255.255.0
access-list 120 extended permit ip any host 192.168.0.0
access-list outside extended permit tcp any host 222.72.138.17 eq smtp
access-list outside extended permit tcp any host 222.72.138.17 eq pop3
access-list outside extended permit tcp any host 222.72.138.17 eq www
access-list outside extended permit tcp any host 222.72.138.17 eq 3389
access-list outside extended permit tcp any host 222.72.138.17 eq 6080
access-list outside extended permit icmp any any
access-list outside extended permit tcp any host 222.72.138.17 eq ftp-data
access-list outside extended permit tcp any host 222.72.138.17 eq ftp
access-list outside extended permit tcp any host 222.72.138.17 eq 3390
access-list inside extended permit ip any any
pager lines 24
mtu outside 1500
mtu inside 1500
mtu guanli 1500
icmp unreachable rate-limit 1 burst-size 1
icmp permit any outside
icmp permit any inside
asdm image disk0:/asdm-512.bin
no asdm history enable
arp inside 192.168.0.50 0040.d0af.13b2
arp timeout 14400
nat-control
global (outside) 1 interface
nat (inside) 1 0.0.0.0 0.0.0.0
alias (inside) 222.72.138.17 192.168.0.251 255.255.255.255
static (inside,outside) tcp interface pop3 192.168.0.251 pop3 netmask 255.255.25
5.255
static (inside,outside) tcp interface smtp 192.168.0.251 smtp netmask 255.255.25
5.255
static (inside,outside) tcp interface 3389 192.168.0.251 3389 netmask 255.255.25
5.255
static (inside,outside) tcp interface 6080 192.168.0.251 6080 netmask 255.255.25
5.255
static (inside,outside) tcp interface ftp-data 192.168.0.251 ftp-data netmask 25
5.255.255.255
static (inside,outside) tcp interface ftp 192.168.0.251 ftp netmask 255.255.255.
255
static (inside,outside) tcp interface www 192.168.0.251 www netmask 255.255.255.
255
access-group outside in interface outside
access-group inside in interface inside
route outside 0.0.0.0 0.0.0.0 222.72.138.1 1
补充下,我用的是WIN SERVER2003做的服务器

问题解答:

不好判断,你先检查一下你的IP地址会不会和别的服务器IP冲突了,有事LINUX系统IP冲突不会报错。

强烈建议大家拨打售前免费热线800-810-5200

可以了解详细情况和解决方案

热点新闻