Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 12-11-2008, 04:02 AM
jet jet is offline
Junior Member
 
Posts: 9
Default [SOLVED] Question on RBL

i'd like to know if it is still necessary to manually add rbl entries in globalsettings->mta of the admin console if i want zimbra to check incoming mails for blacklisted sender ip? i recall reading a post on this forum, saying that zimbra's spamassassin is already performing lookups on some predefined rbl list. i would appreciate if anyone could confirm this.
Reply With Quote
  #2 (permalink)  
Old 12-11-2008, 04:30 AM
Moderator
 
Posts: 7,928
Default

Welcome to the forums

Yes SA will perform RBL lookups by default, if you add RBLs through the Admin then they will be used by Postfix and block at the MTA level without performing any SA checks.
__________________
Reply With Quote
  #3 (permalink)  
Old 12-11-2008, 06:53 AM
Elite Member
 
Posts: 337
Default

Just out of curiosity, is there any place to see if the RBL blocks are actually blocking anything?
Reply With Quote
  #4 (permalink)  
Old 12-11-2008, 06:55 AM
Moderator
 
Posts: 7,928
Default

If you are using them in the MTA then check /var/log/zimbra.log and you should see the rejection message. If you are using them from within SA you will need to increase the logging on amavisd. To do this change the log level too 2 in /opt/zimbra/conf/amavisd.conf.in and then restart ZCS. The additional information will then also appear in /var/log/zimbra.log.
__________________
Reply With Quote
  #5 (permalink)  
Old 12-11-2008, 07:11 AM
Elite Member
 
Posts: 337
Default

Ah, sounds good. We did add zen.spamhaus.org to the RBL list under DNS Check in the global settings. I'll have to browse the zimbra.log sometime to see if it's catching anything.

If I understand you right, if I add an RBL (like spamhaus) to the list, Zimbra uses that and not the spamassassin checks. Would that maybe be why my server statistics graphs for AV/AS activity show nothing for activity?
Reply With Quote
  #6 (permalink)  
Old 12-11-2008, 08:04 AM
Trained Alumni
 
Posts: 74
Default

Check out Configuring and Monitoring Postfix DNSBL - Zimbra :: Wiki

I use it and it emails me everyday with the number of blocked emails using spamhaus RBL. But after a while, I kind of stopped paying attention to it . But it is interesting at the beginning to see how much stuff it blocks.
Reply With Quote
  #7 (permalink)  
Old 12-11-2008, 02:48 PM
jet jet is offline
Junior Member
 
Posts: 9
Default

hi uxbod, if i block mails at the mta level, i get the benefit of conserving on bandwidth because the actual junk mail does not get transmitted. do i get the same benefit if i do it on the level of SA? if so, then blocking at the mta level is totally unnecessary unless you want to include other rbl's not checked by SA or for some reason you want your zimbra installed without the sa/anti-spam feature but still wants to perform rbl lookups.
Reply With Quote
  #8 (permalink)  
Old 12-11-2008, 04:50 PM
Moderator
 
Posts: 1,209
Default

Quote:
Originally Posted by Jbrabander View Post
If I understand you right, if I add an RBL (like spamhaus) to the list, Zimbra uses that and not the spamassassin checks. Would that maybe be why my server statistics graphs for AV/AS activity show nothing for activity?
Not exactly...

If you list an RBL in the Zimbra Postfix and a sending server is on the RBL, Postfix will drop the connection.

Whether you do that or not, SpamAssassin will check a number of RBLs, and a positive response from one or more RBLs will add to the email's spam score. If the score is high enough, the email will be blocked or marked as spam.

Spamassassin has no clue as to whether you are doing RBL lookups in Postfix or not.

And even if you are doing RBL lookups in Postfix, it's still a good idea to keep those same RBL lookups in SpamAssassin IMHO.

Another trick is not to use the Postfix RBL lookups at all, but instead do the RBL lookups on a dedicated Postfix box or firewall in front of your Zimbra box. Since a conservative RBL like Spamhaus's Zen list will catch 85% or more of all spam, doing hard RBL blocking before the entire email stream hits your Zimbra server will reduce the load on your Zimbra server by 85% or more.

You are right that if you do the hard RBL blocking in Postfix your statistics will show a pretty clean email stream overall, because the statistics collect only what Amavis does (SpamAssassin and ClamAV), and not what Postfix blocked outright before passing the email stream off to Amavis.

Hope that helps,
Mark
__________________
___________________________________
L. Mark Stone, CIO


"Uptime. All the time."

477 Congress Street | Portland, ME 04101-3431 | (207) 772-5678

proactive maintenance and monitoring | technology consulting
Zimbra groupware | EMR implementations | private cloud hosting
Reply With Quote
  #9 (permalink)  
Old 12-11-2008, 05:17 PM
jet jet is offline
Junior Member
 
Posts: 9
Default

everything is clear to me now. thanks for everyone's help.
Reply With Quote
  #10 (permalink)  
Old 05-02-2009, 05:48 PM
Active Member
 
Posts: 43
Default

I have added zen.spamhaus.org to the GlobalSettings MTA tab in the Administrator GUI. I have made the necessary checks as outlined in Configuring and Monitoring Postfix DNSBL - Zimbra :: Wiki but I have yet to see any evidence in the Zimbra.log that zen.spamhaus.org is even being used. What could I be doing wrong?

Last edited by GCamp; 05-02-2009 at 05:51 PM..
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.