It has worked with the rules I indicated in my op but then Spam Blocker didn't catch anything.
So while I was thinking about the traffic flow, I remembered suddenly there's NAT on the ASA between the LAN and DMZ meaning that any LAN client address that accessed resources in the DMZ was given a DMZ subnet address too... This meant that the LAN UT would have a random DMZ address and the DMZ UT would never see the original LAN address.
I changed the rule on the DMZ UT from
Hub to Edge
- Source Address 10.165.11.15
- Destination Address 10.165.10.6
to
Lan to Edge
- Source Address 10.165.10.0/24
- Destination Address 10.165.10.6
- Destination port 25
- Protocol TCP
I removed the DMZ UT rule
Edge to Hub
- Source Address 10.165.10.6
- Destination Address 10.165.11.15
and left this one on
Edge to Internet
- Source Address 10.165.10.6
- Destination port 25
- Protocol TCP
The only rule enabled on the LAN UT is
Hub to Edge
- Source Address 10.165.11.15
- Destination Address 10.165.10.6
With both Web and Spam filters on, emails now flow both ways!
Thanks for the help and I'll enjoy digging in deeper to UT's possibilities!
- Individual Applications
Protect
Filter
Perform
Connect
Add-Ons
- Software Packages
- Complete Appliances


LinkBack URL
About LinkBacks
