Re: I'm an open relay and I can't stop

From: Les Mikesell (lesmikesell_at_gmail.com)
Date: 11/05/05

  • Next message: Jay Moore: "Re: Livna.org gone?"
    To: For users of Fedora Core releases <fedora-list@redhat.com>
    Date: Sat, 05 Nov 2005 10:52:02 -0600
    
    

    On Sat, 2005-11-05 at 09:45, Raymond Norton wrote:
    > I am running a server with Fedora core 1, using sendmail-8.12.10-1.1.1. We
    > added proxsmtp to one of our firewalls, so it intercepts mail before
    > sending it on to the mail server. Unfortunately, the box is acting as a
    > relay server now, even though it is set up properly. We are running a
    > 192.168.0, class C internally. I have to add the network in
    > /etc/mail/access, or users get relaying not allowed messages, but this
    > allows the proxsmtp box to act as a relay. Is there to prevent this, but
    > still allow local users to send mail through the server?

    Can you configure the firewall to port-forward port 25 to your
    FC box instead of proxying (i.e. NAT the destination but not
    the source address)? That will let sendmail see the real
    source address and apply your access list rules. If not,
    you may be able to add the firewall address in the access
    rules as OK and the network as RELAY (not sure if a
    more specific match wins but it should).

    Another approach is to require SMTP authentication to relay.
    This takes more setup but most current mail clients support
    it and it will allow your users to send mail even if they
    connect from the internet side as with a roaming laptop
    or cell phone that supports internet email.

    -- 
       Les Mikesell
         lesmikesell@gmail.com
    -- 
    fedora-list mailing list
    fedora-list@redhat.com
    To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
    

  • Next message: Jay Moore: "Re: Livna.org gone?"

    Relevant Pages

    • Re: Unable to Receive Email from the internet
      ... traffic to ther server - requires creating an access rule on the firewall. ... Exchange Server 2007: internet email without Edge ... I'm now able to telnet to port 25 with ... see I'm running into a RELAY problem. ...
      (microsoft.public.exchange.setup)
    • Re: avast
      ... > Just did a clean installation of xp pro sp1 and download 'avast anti ... Did you firewall before connecting to the internet? ... Internet and patch with the critical updates? ... Why you should use a computer firewall.. ...
      (microsoft.public.windowsxp.general)
    • Re: XP NOT RESPONDING
      ... Did you have a firewall going before connecting to the internet? ... Microsoft has these suggestions for Protecting your computer from the ... Why you should use a computer firewall.. ... are pay - some you can only download if you are registered - but it is best ...
      (microsoft.public.windowsxp.setup_deployment)
    • Re: Guide to secure installtion of IIS 5
      ... don't forget a well-configured firewall. ... Do not put the computer onto the network or the Internet until after the ... Follow the instructions for hardening Windows and IIS at ... Install all service packs and security fixes from Microsoft and otherwise ...
      (microsoft.public.inetserver.iis.security)
    • RE: firewall
      ... You need to do a lot of reading about ipfw ... IPFW is the only firewall available to FBSD, ... rules do not function correctly on a DSL or cable internet ... @320 pass in quick on rl0 proto tcp from 63.70.155.0/24 to any port ...
      (freebsd-questions)