Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 06-21-2010, 12:08 AM
Active Member
 
Posts: 38
Default Sending mail on port 25 without authentication

I have set up a zimbra and configured outlook as the mail clients.

I configured my account on outlook on a computer running on the LAN. I then changed the logon information(password) on outlook.

When I open outlook, It asks me for the password. When I click cancel, I can still send mail from the configured account

Does this mean that my zimbra server is an open relay on the LAN? If so, How do I stop this?

I am using port 25 as the "outgoing server".
Reply With Quote
  #2 (permalink)  
Old 06-21-2010, 12:13 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Port 25 does not need authentication, your server is not an Open Relay (I assume you've checked this with an online test?). If you wish to use Authentication then you should use the correct Submission port with is 587 and does require Authentication.
__________________
Regards


Bill
Reply With Quote
  #3 (permalink)  
Old 06-21-2010, 12:19 AM
Active Member
 
Posts: 38
Default

Phoenix,

Thanks for the response. From external networks I am using port 465. this is working fine(my server is not an open relay).

My concern is from the LAN. Can Any outlook masquarade themselves and send mail as if they were another user? Can Spambots running on my LAN use port 25?
Reply With Quote
  #4 (permalink)  
Old 06-21-2010, 12:22 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Quote:
Originally Posted by mutuku View Post
Phoenix,

Thanks for the response. From external networks I am using port 465. this is working fine(my server is not an open relay).
You should use port 587, that is the correct port.

Quote:
Originally Posted by mutuku View Post
My concern is from the LAN. Can Any outlook masquarade themselves and send mail as if they were another user? Can Spambots running on my LAN use port 25?
If you wish to restrict that you need to change the setting in mynetworks that limits the 'Trusted IPs' to the loopback adapter and the IP of the Zimbra server, there are several threads in the forums that have details on what's needed do a search for that.
__________________
Regards


Bill
Reply With Quote
  #5 (permalink)  
Old 06-21-2010, 12:53 AM
Active Member
 
Posts: 38
Default

Quote:
If you wish to restrict that you need to change the setting in mynetworks that limits the 'Trusted IPs' to the loopback adapter and the IP of the Zimbra server
I setup that when I installed the server. My server has 2 network cards...one that is natted to a public IP(IPA), and the other the that connects to the LAN(IPB). All the IPs(IPA, IPB and the loopback) are in the MTA trusted networks list.
Reply With Quote
  #6 (permalink)  
Old 06-21-2010, 02:57 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Quote:
Originally Posted by mutuku View Post
All the IPs(IPA, IPB and the loopback) are in the MTA trusted networks list.
That is incorrect, you should not have the Public IP in there and only have the loopback and the NAT IP of the server in there otherwise you'll be opening up your server to be a relay.
__________________
Regards


Bill
Reply With Quote
  #7 (permalink)  
Old 06-21-2010, 03:13 AM
Active Member
 
Posts: 38
Default

the public IP is not there(MTA trusted networks list). Just the LAN IPs of the 2 network cards of the server. The public IP is natted to one of the mail servers. LAN IPs.Both of the LAN IPs(IPs of the 2 netwotk cards) are MTA trusted networks list. Is this correct?
Reply With Quote
  #8 (permalink)  
Old 06-21-2010, 03:17 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Quote:
Originally Posted by mutuku View Post
the public IP is not there(MTA trusted networks list). Just the LAN IPs of the 2 network cards of the server. The public IP is natted to one of the mail servers. LAN IPs.Both of the LAN IPs(IPs of the 2 netwotk cards) are MTA trusted networks list. Is this correct?
That is the correct configuration and there should be no problem.
__________________
Regards


Bill
Reply With Quote
  #9 (permalink)  
Old 06-22-2010, 04:25 AM
Active Member
 
Posts: 38
Default

I want to mail client access to port 25. Is this possible? I want to migrate to using port 587.
Reply With Quote
  #10 (permalink)  
Old 06-22-2010, 05:54 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Quote:
Originally Posted by mutuku View Post
I want to mail client access to port 25. Is this possible?
There's nothing stopping you using port 25.
__________________
Regards


Bill
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.