I have a client who has a pix 501. They have only allowed me web
access/PDM to configure it. We are doing offsite email
scanning/filtering for them. I would like to create an access rule on
the pix 501 to only accept email from our server. This way, we're sure
it gets scanned. In the event the offsite service is comprimised, I
can just pull that ACL and the backup MX record will take care of mail.
I added a record on the web page which said more or less, the IP
(source) of the mail filter, with 255.255.255.255 as the mask, to the
internal ip of the mail server, and service smtp was allowed. I
actually just edited their current smtp rule. When I did this, mail
would no longer come through. When I removed the specific IP and went
back to any, mail came right through, AND through that mail filter too.
Any help?
