Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 03-08-2011, 11:17 AM
Senior Member
 
Posts: 60
Default amavis - Open relay? Nonlocal recips but not originating:

(Sorry for the dupe. I received a "database error" when posting the first one.)

Greetings,

I recently upgraded from 5.0.21 to 6.0.10 (Open Source).
I noticed a lot of these in the zimbra.log file:

Open relay? Nonlocal recips but not originating: ...

I tested with the Open Relay testers, and the server seems to be OK.
But the messages are still of concern.

Did the customary searches and found this:

[SOLVED] Open Relay amavis warnings in zimbra.log

Not sure if this actually resolves the problem.

Tha amavis list mentioned something about a new warning message with amavisd-new-2.6.4 and settings for "mynetworks" and "originating" ...
(Reference: Old Nabble - Amavis - Open relay, non local recip, mail aliasing and forwarding)

Is there something I missed in the configuration that was either not preserved in the Zimbra upgrade? Is this something new?

Thanks for your time.

Jim

Last edited by blueflametuna; 03-08-2011 at 11:20 AM.. Reason: database error
Reply With Quote
  #2 (permalink)  
Old 03-09-2011, 09:52 AM
Senior Member
 
Posts: 60
Default

I went to examine the settings for the server in the Admin GUI ...
Servers -> <Service host name> -> Edit

and received a Server error pop-up:

! Server error encountered

(Detail):

Message: system failure: exception during auth {RemoteManager: mymail.com->zimbra@mymail.com:22}

But that's another thread ...

Under MTA, the Web mail MTA hostnames is FQDN [mail.mymail.com]
and the list of MTA trusted networks appears correct.

The display is partially broken. It looks like there is a button for [Remove]?
but it is overwritten with another button for [Reset to Global value].
(Cosmetics only, but just noting it.)

Under the Global Settings -> MTA tab, the Web mail MTA Hostnames value is the same as above.

Should this match what is returned by `hostname -f` ?
Reply With Quote
  #3 (permalink)  
Old 03-09-2011, 07:23 PM
Loyal Member
 
Posts: 82
Default

I assume you are running single server. If so set it to localhost.

Details:
[SOLVED] Open Relay amavis warnings in zimbra.log
Reply With Quote
  #4 (permalink)  
Old 03-10-2011, 08:55 AM
Senior Member
 
Posts: 60
Default

I set it to localhost, and I am still receiving the errors.
Reply With Quote
  #5 (permalink)  
Old 03-10-2011, 09:00 AM
Loyal Member
 
Posts: 82
Default

Error from your top post or your 2nd post? Need a bit more details.
Reply With Quote
  #6 (permalink)  
Old 03-10-2011, 09:10 AM
Senior Member
 
Posts: 60
Default

Mar 10 09:08:34 mymail amavis[32600]: (32600-03) Open relay? Nonlocal recips but not originating: user@somewhere.net

I am receiving one for every outbound message.
Reply With Quote
  #7 (permalink)  
Old 03-10-2011, 11:15 AM
Loyal Member
 
Posts: 82
Default

Is the email being sent from web client or from a email program (outlook, etc.) ?

In Admin GUI, under:
Global Settings -> MTA
Server Settings -> MTA
What are the setting for "MTA Trusted Networks"?
Reply With Quote
  #8 (permalink)  
Old 03-10-2011, 11:52 AM
Senior Member
 
Posts: 60
Default

Connections are coming from Web mail client, pop, and imap.

Under Servers -> <Service host name> -> Edit -> MTA ...

MTA Trusted Networks: 127.0.0.0/8 my.ip.addr.0/21 10.110.6.0/24
Reply With Quote
  #9 (permalink)  
Old 03-11-2011, 05:17 PM
Senior Member
 
Posts: 60
Default

One difference I found in the new version of amavis 2.6.4 is this feature:

$policy_bank{'MYNETS'} = {
originating => 1,
allow_disclaimers => 0,
log_level => 1,
};

I am not sure what I need to do to eliminate these warnings.
Reply With Quote
  #10 (permalink)  
Old 03-11-2011, 08:38 PM
Senior Member
 
Posts: 60
Default

I received some help from the new and improved list at amavis.org

The warnings are new to 2.6.4

I needed to set @mynetworks in amavis.conf.

This stopped the warnings for users connecting through the known networks.
But they still display under at least these situations:

* Authenticated users connecting via web client, pop, or imap from outside the network and sending to outside addresses.

* Inbound emails from outside being sent to valid users with forwarding addresses, which then get relayed outbound.

There may be other scenarios, but this cleans it up a lot.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.