Mail Server in the DMZ question

From: Michael Collette (metrol_at_metrol.net)
Date: 05/18/04

  • Next message: Norberto Meijome: "Re: Multi-User Security"
    To: freebsd-security@freebsd.org
    Date: Mon, 17 May 2004 16:39:08 -0700
    
    

    Been trying to puzzle through a firewall layout here involving E-Mail. Would
    have thought this was a more common kind of scenario, but I haven't been able
    to Google me up an answer to this one.

    At present I have an SMTP server (Postfix) in my DMZ that is simply re-routing
    mail into my secure network. This is a less than optimal setup simply due to
    having to allow traffic from the DMZ into my secure network without a
    proceeding request for that data.

    I want to have all the mail held on the server in the DMZ, then have it be
    pulled into the secure network for all my users by some means.

    Originally I thought I could just setup a multi-drop box, pull in the mail
    with Fetchmail, then have it delivered to my internal server for processing.
    Seems that there are way too many pitfalls for this setup to reasonably
    support all my users.

    I then looked into configuring the DMZ server to hold all mail, then release
    on an ETRN request. From what I've read on this I'm really no better off, as
    I still have to allow port 25 requests into my secure network.

    Thanks,

    -- 
    "In theory, there is no difference between theory and practice.
    In practice, there is."
    - Yogi Berra
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Norberto Meijome: "Re: Multi-User Security"

    Relevant Pages

    • Re: Mail Server in the DMZ question
      ... > to come from the DMZ into the secure network didn't seem right. ... > mail in the DMZ then request it down into the secure network. ... All UUCP offers is that it's a "pull" technology, ...
      (FreeBSD-Security)
    • Re: SBS2000 and a DMZ
      ... The whole purpose of the DMZ is to prevent this ... in order to keep it secure and do what you need to do. ... The Win2k3 server can probably be safely inserted on the SBS domain and only ...
      (microsoft.public.backoffice.smallbiz2000)
    • Re: Choice of DNS version in mixed Windows NT 4 domain Environment
      ... > or newer DNS. ... >> internal trusted network to access the websites on the server using the ... >> ISP directs the request to my DMZ. ...
      (microsoft.public.windows.server.dns)
    • Choice of DNS version in mixed Windows NT 4 domain Environment
      ... I have set up an IIS web server on my DMZ and I want my clients on the ... I am currently using my ISP's DNS, so when the web request is resolved, my ... ISP directs the request to my DMZ. ...
      (microsoft.public.windows.server.dns)
    • Re: Location behind Firewall
      ... how about publishing your exchange server using ISA 2004 in DMZ while your ... B/E server still resides in your secure network? ... other ports than SSL. ...
      (microsoft.public.exchange.design)