Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
 
Go Back   Zimbra - Forums > Zimbra Collaboration Suite > Installation

Welcome to the Zimbra - Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 06-29-2007, 09:39 AM
Senior Member
 
Posts: 63
Default emergency, how do I disable an open relay in zimbra?

I'm trying in vain to stop the tens of thousands of emails being pumped into my server, which should not have an open relay.

I need to disable the open relay.
Reply With Quote
  #2 (permalink)  
Old 06-29-2007, 10:11 AM
Zimbra-Yahoo Consultant
 
Posts: 5,608
Default

Open relay is off by default.
1) Can you provide the /var/log/zimbra.log to prove that open relay is open?
2) Have you done an open relay test?
Reply With Quote
  #3 (permalink)  
Old 06-29-2007, 10:29 AM
Senior Member
 
Posts: 63
Default

Quote:
Originally Posted by jholder View Post
Open relay is off by default.
1) Can you provide the /var/log/zimbra.log to prove that open relay is open?
2) Have you done an open relay test?
1) logging doesn't work unless I reboot!
2) 35,000 emails from yahoo.tw prove the relay is open!

HOW DO I DISABLE IT!

[SHOT]http://www.powerslife.net/james/spam-in-queue.jpg[/SHOT]

Last edited by jptech : 06-29-2007 at 10:47 AM.
Reply With Quote
  #4 (permalink)  
Old 06-29-2007, 10:39 AM
OpenSource Builder & Moderator
 
Posts: 1,158
Default

Quote:
2) 35,000 emails from yahoo.tw prove the relay is open!

HOW DO I DISABLE IT!
NO IT DOESNT!

Post logs to prove your zimbra install is relaying externally.
Reply With Quote
  #5 (permalink)  
Old 06-29-2007, 10:48 AM
Senior Member
 
Posts: 63
Default

I don't have logs because the logger doesn't work.

no one seems to want to help me in acutally disabling the open relay.

I don't need to argue over whether it's open or not.

I need to close it.
Reply With Quote
  #6 (permalink)  
Old 06-29-2007, 10:58 AM
Zimbra-Yahoo Consultant
 
Posts: 5,608
Default

Calm down.

Your supposition is incorrect. If we had open relay on by default, then we would have noticed.

Now, if someone is using a username and password on your network, that they got a hold of, then it's possible someone is using your e-mail server as a relay.

Unless you provide the /var/log/zimbra.log, we won't be able to help you.

(PS quit typing in all caps.)
Reply With Quote
  #7 (permalink)  
Old 06-29-2007, 11:02 AM
Zimbra-Yahoo Consultant
 
Posts: 5,608
Default

Looks to me like someone has outlook, and their machine is infected. What's 192.168.0.1?
Reply With Quote
  #8 (permalink)  
Old 06-29-2007, 11:04 AM
Senior Member
 
Posts: 63
Default

192.168.0.1 is the firewall.

it uses ip masquerading to provide access to the MTA.

it's not in the postfix 'mynetworks' declaration

I had to remove the masq to disable internet access to the MTA before the spam would stop!

Last edited by jptech : 06-29-2007 at 11:09 AM.
Reply With Quote
  #9 (permalink)  
Old 06-29-2007, 11:07 AM
Zimbra-Yahoo Consultant
 
Posts: 5,608
Default

Can you pvt me your domain name so I can run some tests?

It may be that Open Relay got turned on. . .I'm not saying it's not on. You SS looks like it is.

But it is off by default.
Reply With Quote
  #10 (permalink)  
Old 06-29-2007, 11:18 AM
Zimbra-Yahoo Consultant
 
Posts: 5,608
Default

jptech is correct.
His server is being used as an open relay.

To ensure that we aren't shipping it that way, I tested 4.5.4, 4.5.5, and 4.5.6
None have this feature on by default.
Reply With Quote
Reply


Thread Tools
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

Zimbrablog.com




 

Search Engine Optimization by vBSEO 3.1.0