Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 04-01-2008, 03:06 AM
New Member
 
Posts: 3
Default mail delivery queued after configuring linux firewall

Guys,

My ZCS has been working perfectly for a few days now with both web client and pop3 client access from the net.

I enabled and configured my linux server firewall (according to the wiki), I can send emails but the cannot receive.

I noticed that all incoming mails gets queued and not delivered to individual mail boxes.

My server is directly connected to the net with public IP (thats why I want to setup the firewall).

heres my port setings:
# Accept Zimbra ports
-A INPUT -p tcp -m tcp -m state --dport 25 --state NEW -j ACCEPT
-A INPUT -p tcp -m tcp -m state --dport 80 --state NEW -j ACCEPT
-A INPUT -p tcp -m tcp -m state --dport 110 --state NEW -j ACCEPT
-A INPUT -p tcp -m tcp -m state --dport 143 --state NEW -j ACCEPT
-A INPUT -p tcp -m tcp -m state --dport 389 --state NEW -j ACCEPT
-A INPUT -p tcp -m tcp -m state --dport 443 --state NEW -j ACCEPT
-A INPUT -p tcp -m tcp -m state --dport 465 --state NEW -j ACCEPT
-A INPUT -p tcp -m tcp -m state --dport 993 --state NEW -j ACCEPT
-A INPUT -p tcp -m tcp -m state --dport 7993 --state NEW -j ACCEPT
-A INPUT -p tcp -m tcp -m state --dport 995 --state NEW -j ACCEPT
-A INPUT -p tcp -m tcp -m state --dport 7995 --state NEW -j ACCEPT
-A INPUT -p tcp -m tcp -m state --dport 7071 --state NEW -j ACCEPT
-A INPUT -p tcp -m tcp -m state --dport 7025 --state NEW -j ACCEPT
-A INPUT -p tcp -m tcp -m state --dport 8080 --state NEW -j ACCEPT

Am I missing something? Do I need additional admin cnfiguration?

Robert
Reply With Quote
  #2 (permalink)  
Old 04-01-2008, 03:23 AM
Zimbra Consultant & Moderator
 
Posts: 20,312
Default

If you followed the wiki article you seem to have missed port 22 & 161 that it also lists. What error messages are you seeing in the logs?
__________________
Regards


Bill
Reply With Quote
  #3 (permalink)  
Old 04-01-2008, 03:56 AM
Moderator
 
Posts: 7,928
Default

Is the INPUT chain being tied down ? if not and you open up 22 and 161 to the world you may get a lot of nosey people probing your server
__________________
Reply With Quote
  #4 (permalink)  
Old 04-01-2008, 04:43 AM
New Member
 
Posts: 3
Default

Sorry SSH is also open, I just did not think its necessary to for ZCS to work properly thats why i did not include it on the list.

I dont have active logging (which is my next problem). I can see the incoming emails on the admin site Mail Queues list under deferred column.

That means emails are reaching the server but it just cannot be delivered to the right box

Robert
Reply With Quote
  #5 (permalink)  
Old 04-01-2008, 04:49 AM
Moderator
 
Posts: 7,928
Default

As Phoenix said in his previous post please check your Log Files - Zimbra :: Wiki as this should show why things are being deferred.
__________________
Reply With Quote
  #6 (permalink)  
Old 04-01-2008, 04:55 AM
Zimbra Consultant & Moderator
 
Posts: 20,312
Default

Quote:
Originally Posted by infomate View Post
Sorry SSH is also open, I just did not think its necessary to for ZCS to work properly thats why i did not include it on the list.

I dont have active logging (which is my next problem). I can see the incoming emails on the admin site Mail Queues list under deferred column.

That means emails are reaching the server but it just cannot be delivered to the right box

Robert
The likelihood is that you'll need a Split DNS set-up as you're behind the firewall, Postfix probably can't resolve the Zimbra server IP address.
__________________
Regards


Bill
Reply With Quote
  #7 (permalink)  
Old 04-01-2008, 05:03 AM
Moderator
 
Posts: 7,928
Default

Quote:
Originally Posted by infomate View Post
My server is directly connected to the net with public IP (thats why I want to setup the firewall).
If the server is on a public IP why would a split DNS be required ?
__________________
Reply With Quote
  #8 (permalink)  
Old 04-01-2008, 07:19 AM
Outstanding Member
 
Posts: 684
Default

If the mail is being queued, it's coming through the firewall. Since you say it's being queued but not delivered to the individual mailboxes, I don't think it's a firewall issue.
Reply With Quote
  #9 (permalink)  
Old 04-03-2008, 06:12 PM
New Member
 
Posts: 3
Default

Thank you guys for the replies.

As I mentioned above that my log is not working, I was able to find out that under Fedora 8 the logger should rsyslog not syslog, after fiddling for a few days I finally got it to log.

Back to my main prob. As per Bill, I was thinking in the same line, that its not a firewall issue. But thats the only thing I did that caused the mails to get stuck in que. After re-doing the same 3 times (activating and deactivating the firewall) It suddenly worked with not problems.


Next question is, how robust would my system be, facing the net with public IP with just the linux firewall to defend it? should another router/firewall be necessary?

Are there other ways to harden zimbra?

Again thanks guys
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.