FW: Problems with Exchange 2000 as open relay

From: Haluk Aydin (haydin_at_BIZNET.COM.TR)
Date: 12/19/03

  • Next message: Yuval Kashtan: "Upcoming Windows XP SP2 NX feature"
    Date:         Fri, 19 Dec 2003 11:43:05 +0200
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    >Few would ever need to configure a firewall to NAT like that (both the
    >source and destination address) the source IP address of an incoming
    >packet never changes through a typical (simple) firewall NAT. These are
    basic concepts of NAT and Routing TCP/IP.

    Yes NAT does not change the source address, but if they are using a
    firewall with smtp proxy, the incoming packets seem to come from
    internal network. You can check several firewalls like Checkpoint's smtp
    resource (or security server).

    Haluk AYDIN

    -----
    Most viruses these days use spoofed email addresses. As such, using an Anti-
    Virus product which automatically notifies the perceived sender of a message
    it believes is infected may well cause more harm than good. Someone who did
    not actually send you a virus may receive the notification and scramble
    their support staff to find an infection which never existed in the first
    place. Suggest such notifications be disabled by whomever is responsible for
    your AV, or at least that the idea is considered.
    -----


  • Next message: Yuval Kashtan: "Upcoming Windows XP SP2 NX feature"

    Relevant Pages

    • Re: NAT vs. True Firewalls
      ... > not just mean packet filter. ... A firewall can be made up of one or more ... > components that can block or filter protocol traffic between two networks. ... So a NAT can be as much part of a firewall implementation as ...
      (comp.security.firewalls)
    • [fw-wiz] Checkpoint and RTSP NAT
      ... The clients are behind a Checkpoint NGX firewall doing NAT. ... Capturing packets i saw that the NAT in the Checkpoint box is the problem. ... packet from server when de-NATing the packet: ... Did anyone knows if Checkpoint NGX can be awareness of RTSP when using NAT, ...
      (Firewall-Wizards)
    • Re: TFTP, NAT
      ... With NAT yes, but behind a firewall, you have to have a very good reason. ... > was the destination of the UDP packet that caused the entry to be created. ...
      (comp.os.linux.networking)
    • Re: home network behind NAT and firewall ?
      ... >> real Firewall appliance with more than 20 systems at any given time. ... >> firewall provides for the ability to assign both public (not nat) and ... that would reset the router and allow remote control - it was noted ... >> LAN inside their network and it would never have to reach the ISP's ...
      (comp.security.firewalls)
    • Re: NAT vs. True Firewalls
      ... not just mean packet filter. ... A firewall can be made up of one or more ... components that can block or filter protocol traffic between two networks. ... So a NAT can be as much part of a firewall implementation as the ...
      (comp.security.firewalls)