Ipchains and smtp rule

From: Mogens Valentin (monz@danbbs.dk)
Date: 11/19/01


Message-ID: <3BF93982.11D39BA3@danbbs.dk>
Date: Mon, 19 Nov 2001 17:55:30 +0100
From: Mogens Valentin <monz@danbbs.dk>
To: focus-linux <focus-linux@securityfocus.com>
Subject: Ipchains and smtp rule

I don't understand a thing.
I have a mailserver outside a firewall (I'm missing a switch for the
dmz):

  inet ---+--- firewall --- internal net
          +--- mailserver

The policy is deny everything, allow any outgoing, then allow incoming
as per needed service.
Everything works, including simap to the outdoors mailserver (also
running courier-imap), except for sending mail.

Neither
  ipchains -A -p tcp -s 0/0 -d 0/0 smtp -j accept or even
  ipchains -A input -p tcp -i $PUBLICIFC ! -y -j ACCEPT
does the job.

Using /proc/net/* settings, I generally move trafic to high ports.
Tcpdump showed smtp connects to highports, AFAICT. Sure, I may be
mistaken.
I don't remember seeing smtp on highports, any comments?

If I temporarily allow any traffic on all interfaces, smtp works, so the
mailserver is working.

There's a whole bunch of rules, so please ask for what's needed.

-- 
Regards,
           Mr Dev - Mogens Valentin
    http://www.mrdev.com - mrdev@danbbs.dk
OpenSource Security - Networking - Programming



Relevant Pages

  • Re: earthlink users problem
    ... receiving SMTP mail directly into your Exchange Server ... Do some of your users have Earthlink personal accounts and have set that up ... this to your mailserver administrator in the event that you do not fulfill ... delivery attempts through the 'A' record will consequently fail ...
    (microsoft.public.windows.server.sbs)
  • Re: Intersite Communications
    ... mailserver it should go via SMTP, ... server) - they communicate via X.400/MTA...). ... Sydney and one called Melbourne... ... e-mail to Melbourne 2003 via SMTP? ...
    (microsoft.public.exchange.connectivity)
  • Re: smtp server error
    ... Warning: mail: SMTP server response: 451 Request action aborted; ... When I change it to my ISP mailserver, ... # Reply at the bottom and on a empty line, not behind any>>> sign # Ik lees alleen mail gepost naar onderstaand adres. ... I only read mail sent to the adres at the bottom. ...
    (alt.php)
  • Re: smtp server error
    ... Warning: mail: SMTP server response: 451 Request action aborted; ... When I change it to my ISP mailserver, ... # Reply at the bottom and on a empty line, not behind any>>> sign # Ik lees alleen mail gepost naar onderstaand adres. ... I only read mail sent to the adres at the bottom. ...
    (comp.lang.php)
  • Re: HILFE SMTP empfängt tausende Emails
    ... > auf den SMTP haben? ... Zugriff ungleich Relaying. ... per SMTP AUTH am Mailserver anmelden. ... DynFX MailServer 2.2 fuer Windows NT/2K/XP/03 ...
    (microsoft.public.de.inetserver.iis)