73-11
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter73 E-Mail Proxy
Delimiters
Fields
POP3S/IMAP4S/SMTPS Default Server—Let you configure a default server, port and
non-authenticated session limit for e-mail proxies.
Name or IP Address—Type the DNS name or IP address for the default e-mail proxy server.
Port—Type the port number on which the ASA listens for e-mail proxy traffic. Connections are
automatically allowed to the configured port. The e-mail proxy allows only SSL connections on this
port. After the SSL tunnel establishes, the e-mail proxy starts, and then authentication occurs.
For POP3s the default port is 995, for IMAP4S it is 993, and for SMTPS it is 988.
Enable non-authenticated session limit—Select to restrict the number of non-authenticated e-mail
proxy sessions.
E-mail proxy connections have three states:
1. A new e-mail connection enters the “unauthenticated” state.
2. When the connection presents a username, it enters the “authenticating” state.
3. When the ASA authenticates the connection, it enters the “authenticated” state.
This feature lets you set a limit for sessions in the process of authenticating, thereby preventing DOS
attacks. When a new session exceeds the set limit, the ASA terminates the oldest non-authenticating
connection. If there are no non-authenticating connections, the oldest authenticating connection is
terminated. The does not terminate authenticated sessions.
Delimiters
Configuration> Features > VPN > E-mail Proxy > Delimiters
This panel lets you configure username/password delimiters and server delimiters for e-mail proxy
authentication.