Re: what's wrong with my sendmail?


Subject: Re: what's wrong with my sendmail?
From: shortpier (shortpier@shortpier.is-a-geek.com)
Date: Tue Nov 11 2003 - 20:22:07 AKST


On Thu, 2003-11-13 at 12:28, Justin Dieters wrote:
> It is behind a smoothwall box, on the DMZ. The smoothwall box only
> forwards ports 22, 80, and 25.
>
> As far as the server itself goes, this is what /sbin/route has,
> 192.168.0.1 being the smoothwall box:
>
> Destination Gateway Genmask Flags Metric Ref Use Iface
> 192.168.0.0 * 255.255.255.0 U 0 0 0 eth0
> 127.0.0.0 * 255.0.0.0 U 0 0 0 lo
> default 192.168.0.1 0.0.0.0 UG 0 0 0 eth0
>
understood.. Late at night dealing with couple of puking kids and I was
not the clearest in what I wrote ...
I was trying to make an example of HOW you could do it on a box to route
to <your side> a private IP from a Private IP over the Public Inet (no
vpn) Your machine Does not need a return route... On and will send email
from any local machine IE 192.168.0.1 to 192.168.0.254...

SO I add a route
route add 192.168.0.0/255.255.255.0 gw 24.237.2.79

If your smoothwall is just forwarding the port AUTOMATICLY Before
firewall rules ( I dont know smoothwall I use shorewall on Mandrake)
Then your server in the DMZ accepts the traffic on port 25.... Sees
that it is from a "local" machine on a Local IP addy.. and A local
interface and Says Ok thanks ... Ill send this right out for you.....

May or may not be the prob... But I can see it happening ..... Almost
supprised that I have not yet seen any thing on a new spammer tool just
to do this.... IIS box behind Consumer router on broadband? OUCH......
Makes my head hurt....

My own mail server has to Ifaces.... One it will accept traffic on for
mail Incoming and outgoing, One that will only let outgoing traffic
pass it...
  

Shortpier
>
> Justin
>
>
> shortpier wrote:
> > Does your mail servber have any firewall rules?? ... IE does the IP of
> > the src comp have to match the netmask?... One way I could see this is a
> > manual route on a machine with your EXTERNAL ip being the gateway to
> > your internal ip ....
> >
> > IE route add <internal private IP> gw <external IP> and if that is the
> > case you will route anybody and relay for anybody who has the routing
> > info...
> >
> > Shortpier
>
> ---------
> To unsubscribe, send email to <aklug-request@aklug.org>
> with 'unsubscribe' in the message body.

-- 

-- Attached file included as plaintext by Listar -- -- File: signature.asc -- Desc: This is a digitally signed message part

-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQA/scN/NyWzwlj5xp4RAoEAAKCLQvqAqDzmQ5aPrWgeka6k2KN3eQCfZ5XC tR9cioMCdJF4Qn6uCSDH+Ho= =AJkX -----END PGP SIGNATURE-----

--------- To unsubscribe, send email to <aklug-request@aklug.org> with 'unsubscribe' in the message body.



This archive was generated by hypermail 2a23 : Thu Nov 13 2003 - 13:54:27 AKST