class-map inspection_default
match default-inspection-traffic
!
policy-map type inspect esmtp tls-esmtp
parameters
allow-tls

policy-map global_policy
class inspection_default
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
inspect icmp
inspect esmtp tls-esmtp

!

!--- This command tells the device to
!--- use the "global_policy" policy-map on all interfaces.

service-policy global_policy global
!
!

The Extended Simple Mail Transport Protocol (ESMTP) inspect feature masks the hostname and causes
an error when a mailserver is configured to ensure the HELO reply is a valid hostname.

ESMTP fixup has a feature that removes some header information that is not required by the RFCs from the
responses. Sometimes this un-required data is used by mail servers to try and limit spam.

For example, mail fails when a user enters the helo command instead of the HELO command.

The HELO command must be used as stated by the RFC 821 specifications when inspect esmtp is enabled.

hostname (config)#policy-map type inspect esmtp testesmtpmap
hostname (config-pmap)#parameters
hostname(config-pmap-p)#no mask-banner
!
hostname(config)#policy-map global_policy
hostname(config-pmap)#class inspection_default
hostname(config-pmap-c)#no inspect esmtp
hostname(config-pmap-c)#inspect esmtp testesmtpmap
!
hostname(config)#service-policy global_policy global


default-inspection-traffic.  Match default inspection traffic:

ctiqbe—-tcp–2748
dns——-udp–53
ftp——-tcp–21
gtp——-udp–2123,3386
h323-h225-tcp–1720
h323-ras–udp–1718-1719
http——tcp–80
icmp——icmp
ils——-tcp–389
mgcp——udp–2427,2727
netbios—udp–137-138
radius-acct—udp–1646
rpc——-udp–111
rsh——-tcp–514
rtsp——tcp–554
sip——-tcp–5060
sip——-udp–5060
skinny—-tcp–2000
smtp——tcp–25
sqlnet—-tcp–1521
tftp——udp–69
waas——tcp–1-65535
xdmcp—–udp–177