The easiest way to determine the issue would be to set up packet captures on the ASA :
Configure Packet Capture on ASA :
Wan Inbound Traffic :
access-list CAPOUT extended permit tcp object-group Messagelabs any
access-list CAPOUT line 2 extended deny tcp any any eq 25
!
!
Lan Inbound Traffic :
access-list CAPIN extended permit tcp host 172.16.0.125 any eq 25
access-list CAPIN line 2 extended deny tcp any any eq 25
!
!
Bind to Interface :
cap CAPIN access-list CAPIN interface inside
cap CAPOUT access-list CAPOUT interface outside
You can check the captures with :
show cap CAPIN
show cap CAPOUT
!
Packet Capture :
show capture CAPIN detail packet-number 5 dump
show capture CAPOUT detail packet-number 5 dump
!
Display <number> of packets in capture :
show capture CAPOUT count 10
Comments
(There are currently no comments for this post.)