Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 12-22-2010, 12:22 AM
User Awaiting Moderation
 
Posts: 19
Default Force smtp authentication!

Hi there

I configured the MTA with Enable authentication and TLS authentication only. Everything works well, all the mail client have to set "My outgoing server (SMTP) requires authentication" and use 465 (SSL) to send mail.

Now i found that I can telnet to port 25 (from and LAN machine) and do send mail without any authentication (the mail client still required)

I still control my trusted network list.

Any ideas?
Reply With Quote
  #2 (permalink)  
Old 12-22-2010, 03:02 AM
Zimbra Consultant & Moderator
 
Posts: 20,313
Default

Quote:
Originally Posted by lmthong View Post
Hi there

I configured the MTA with Enable authentication and TLS authentication only. Everything works well, all the mail client have to set "My outgoing server (SMTP) requires authentication" and use 465 (SSL) to send mail.
You actually should be using the correct Submission port which is 587.

Quote:
Originally Posted by lmthong View Post
Now i found that I can telnet to port 25 (from and LAN machine) and do send mail without any authentication (the mail client still required)
Of course you can do that, what would you expect to happen? The LAN users are in your Trusted Network settings, did you search for this in the forums (you should, it's been covered many times)?
__________________
Regards


Bill
Reply With Quote
  #3 (permalink)  
Old 12-22-2010, 03:56 AM
User Awaiting Moderation
 
Posts: 19
Default

Sorry, but I did search.

By the way, how can i remove LAN out of Trusted Network. I saw there's only 127.0.0.0/8, zimbra-mailbox-server-ip,zimbra-mta-server-ip.

And why the LAN users can not send mail if the mail client doesnot set to "My outgoing server (SMTP) requires authentication" but the telnet?
Reply With Quote
  #4 (permalink)  
Old 12-22-2010, 03:59 PM
Elite Member
 
Posts: 334
Default

Quote:
Originally Posted by lmthong View Post
Sorry, but I did search.

By the way, how can i remove LAN out of Trusted Network. I saw there's only 127.0.0.0/8, zimbra-mailbox-server-ip,zimbra-mta-server-ip.

And why the LAN users can not send mail if the mail client doesnot set to "My outgoing server (SMTP) requires authentication" but the telnet?
To remove your LAN from trusted network, mark your Zimbra ip with /32 subnet instead of the default /24, so your trusted network should be look like this :

127.0.0.0/8 192.168.10.1/32 (if your Zimbra IP = 192.168.10.1)

Why your client need SMTP auth because you force it to use TLS only.
__________________
Best Regards
---
Masim "Vavai" Sugianto
Vavai Personal Blog
Personal Blog [ID]

Release 7.1.3_GA_3346.SLES11_64_20110930001521 SLES11_64 FOSS edition.
Reply With Quote
  #5 (permalink)  
Old 12-23-2010, 12:04 AM
User Awaiting Moderation
 
Posts: 19
Default

Quote:
Originally Posted by vavai View Post
To remove your LAN from trusted network, mark your Zimbra ip with /32 subnet instead of the default /24, so your trusted network should be look like this :

127.0.0.0/8 192.168.10.1/32 (if your Zimbra IP = 192.168.10.1)

Why your client need SMTP auth because you force it to use TLS only.
Sure, except loopback address, all other Trust Network was /32.

Now the MTA is "TLS authentication only" but why the port 25 still allow send mail without any authentication (test by telnet mta.mydomain.com 25). And why the mail client (like MS outlook, outlook express) have to set "My outgoing server (SMTP) requires authentication" (this is what I expect). I'm taking about LAN users.

more clear: I put my MTA in DMZ, trusted network is: 127.0.0.0/8, zimbra-mailbox-ip/32,zimbra-mta-ip/32 and nothing else

Last edited by lmthong; 12-23-2010 at 12:22 AM..
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.