QMail relaying with firewall
Running FC4. Have set up and configured QMail okay.
Now have set up a firewall where the QMail box is in the DMZ
(192.168.2.0). I want QMail to allow relaying for any host on the
inside network (192.168.1.0). I set up tcpserver rules as follows:
127.:allow, RELAYCLIENT=""
192.168.1.:allow, RELAYCLIENT=""
I know that the firewall (Cisco PIX) changes the source IP that gets
sent to the QMail box. The logs show 192.168.2.1, which is the PIX DMZ
IP. But even if I add that IP to the rules, I still can't relay from a
host on the inside.
Has anyone gotten a setup like this to work? I am guessing that this
is more a firewall issue, but was hoping someone had a solution.
TIA
ken AT softsteps DOT com
.
Relevant Pages
- Watchguard II (2) and qmail
... I have qmail on a stripped down linux machine whose configuration ... firewall running sendmail and the NAT for them works perfectly fine. ... Is there some issue with Watchguards, NAT, and qmail? ... (comp.security.firewalls) - Re: Need help setting up qmail / binc imap on FreeBSD
... > I am trying to implement a qmail based mailserver with binc imap on FreeBSD ... I assume your firewall allows all connections from localhost. ... Maybe on the server itself try localhost for to eliminate ... So you have a permissions problem for qmail. ... (freebsd-questions) - Firewall questions
... FreeBSD for two months now. ... systems that may be using the POP mail. ... which was contributed by a qmail ... Any suggestions as to what firewall would provide me ... (freebsd-questions) - Re: OT: Setting up a forwarding mail domain in DMZ without pinhole.
... > But am really amazed to hear about this feature of postfix and look for ... > a qmail implementation of this....though I dont think any exists. ... > maps similar to postfix, ... communication which is blocked by the firewall. ... (Fedora) - Configuring PIX Firewall
... I'm having to configure a PIX 515e firewall that's on our network, but know very little about networking. ... Cisco PIX Device Manager Version 3.0 ... I'd like to divvy up 1.2.3.130-254 between the internal and dmz, but it seems like the best I can do is give 32 addresses to the dmz and 64 to the internal, and then the other 32 are wasted on the outside interface. ... (comp.security.firewalls) |
|