Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 02-13-2011, 05:44 PM
Junior Member
 
Posts: 5
Default Local relay

Hi,

Our Zimbra (open source) is allowing local relay without authentication.

E.g.:

1@zimbra.xxx > 2@zimbra.xxx without authentication.

I want to be mandatory an authentication even local domain.

How can i modify postfix to have a mandatory authentication?

Thanks.
Reply With Quote
  #2 (permalink)  
Old 02-13-2011, 06:56 PM
Active Member
 
Posts: 39
Default

Admin Cosole -> Server Settings -> MTA -> MTA Trusted Networks

Remove your local network from here, and place only external IP of zimbra server like this 127.0.0.0/8 192.168.100.10/32.

By default zimbra accept whole network of external interface like trusted network and don't ask authentication
Reply With Quote
  #3 (permalink)  
Old 02-13-2011, 07:01 PM
Junior Member
 
Posts: 5
Default

Already did. 127.0.0.0/8 xxx.xxx.xxx.xxx/29.

Didnt work.
Reply With Quote
  #4 (permalink)  
Old 02-13-2011, 08:37 PM
Active Member
 
Posts: 39
Default

From what IP addres you try to connect to your server and try to relay message? Mask /29 contains 6 host, maybe you try to relay from one of that 6 hosts?
Reply With Quote
  #5 (permalink)  
Old 02-14-2011, 04:16 AM
Junior Member
 
Posts: 5
Default

Quote:
Originally Posted by mavlenko View Post
From what IP addres you try to connect to your server and try to relay message? Mask /29 contains 6 host, maybe you try to relay from one of that 6 hosts?
Yeah, we trying from another ip from same /29. But i really want authenticate, even in our /29.

Outside our /29 using @zimbra.xxx > @zimbra.xxx works too.

(Just for understanding, another company used our zimbra.xxx to send an e-mail from a CIO to CEO asking for resignation...)
Reply With Quote
  #6 (permalink)  
Old 02-14-2011, 03:17 PM
Junior Member
 
Posts: 5
Default

If i remove my own /29 from trusted networks? Is that safe? Works?
Reply With Quote
  #7 (permalink)  
Old 02-14-2011, 07:30 PM
Active Member
 
Posts: 39
Default

I think we're talking about different things, relaying entails sending mail outside your domain which hosted on your zimbra. Within the domain - it does not relay.
Quote:
If i remove my own /29 from trusted networks? Is that safe? Works?
you needn't remoove whole network, you must leave your external IP of zimbra server and IP of trusted hosts in your network as i told 127.0.0.0/8 192.168.100.10/32 10.10.10.40/32. It's safe and works.
Trusted networks mean that only those hosts can relay mails throught your server to another domains, it's may be another mail-server (zimbra, exchange etc) or something like a mail-robot.
Reply With Quote
  #8 (permalink)  
Old 02-16-2011, 02:32 AM
Junior Member
 
Posts: 5
Default

I removed from trusted networks and tested out of our structure (at datacenter) a 0-day Zimbra installation and local still not require authentication. So, how can i make mandatory authentication for @zimbra.xxx to @zimbra.xxx ?

Thanks!

Last edited by rasga; 02-16-2011 at 02:41 AM..
Reply With Quote
  #9 (permalink)  
Old 02-16-2011, 07:48 PM
Active Member
 
Posts: 39
Default

I think you need to read this smtp authentication and some other thread on the forum about authentication and relaying to anderstand that zimbra allways accept mails for internal domains without authentication, and ask authentication only for send mesaages to other domains. So, answer to your first post is: "No, it is impossible to have an authentication for local domains"
I was a little bit stupid when answering your question. I told about an external relay, and you asked about internal. Sorry
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.