Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 07-25-2011, 07:52 AM
Starter Member
 
Posts: 1
Question Restricting Local Relay

I've searched the forums, but I apologize if I have missed something obvious. I've seen threads, like Local relay which seek to restrict local relay to authenticated users, but not exactly in my situation.

I understand a mail server normally needs to allow unauthenticated users to send mail to local mailboxes to facilitate the normal operation of E-mail, but I still wish to restrict local relay to authenticated users, or local network hosts only.

We have a spam firewall device at the edge of our network that we use to receive E-mail from the internet at large, and it does a fantastic job of filtering spam which in turn reduced the load on the Zimbra server, everyone is happy.

The only problem is, Zimbra allows any spammer clever enough to waltz right in and bypass the spam filter, if they connect to the zimbra SMTP server directly. Of course they can't relay to the general internet, but they can spam all of our local mailboxes with impunity.

I know I could restrict access at the network level, and require my legitimate clients to relay through the spam filter as well, but I would prefer leaving the setup as it is, and just requiring Zimbra to enforce authentication for ALL users.

Is there ANY way in zimbra 6 to have this restriction? I am not opposed to hacking around in the postfix configuration every time I upgrade if that's what it takes.


Thanks for reading, and doubly so for any assistance you can provide!
Reply With Quote
  #2 (permalink)  
Old 07-25-2011, 08:11 AM
Zimbra Consultant & Moderator
 
Posts: 20,314
Default

Quote:
Originally Posted by AWnet View Post
The only problem is, Zimbra allows any spammer clever enough to waltz right in and bypass the spam filter, if they connect to the zimbra SMTP server directly. Of course they can't relay to the general internet, but they can spam all of our local mailboxes with impunity.
How do you reckon they're bypassing the spam 'filter'? Do you mean your edge spam filetr or the Zimbra anti-spam system? How can they get to port 25 on the Zimbra server when it's (should be) pointed at your edge spam filter?


Quote:
Originally Posted by AWnet View Post
I know I could restrict access at the network level, and require my legitimate clients to relay through the spam filter as well, but I would prefer leaving the setup as it is, and just requiring Zimbra to enforce authentication for ALL users.
Your users should be using Port 587 (the correct Submission port) not port 25 for mail delivers, Port 587 requires Authentication.

Quote:
Originally Posted by AWnet View Post
Is there ANY way in zimbra 6 to have this restriction? I am not opposed to hacking around in the postfix configuration every time I upgrade if that's what it takes.!
You could always remove your LAN subnet from the Trusted Networks and force every local user to authenticate, obviously you'd need to add the IP of your edge spam filter in that setting if you don't want to to authenticate.
__________________
Regards


Bill
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.