OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Adrian Bolzan (Adrian.Bolzanaot.com.au)
Date: Thu Jan 03 2002 - 01:35:09 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    On 3 Jan 2002 at 7:12, Ralf Hildebrandt wrote:

    > On Thu, Jan 03, 2002 at 01:15:44PM +1000, Adrian Bolzan wrote:
    >
    > > thanks for that tip. There has been some comment on the fact that anti-
    > > virus software does not run in a chrooted jail, and runs as root.
    >
    > Talk about "professional software".
    >

    point taken.

    > > For in:
    > > Internet --> Postfix (Header/body matching, on DMZ)
    > > --> Postfix + Antivirus (on DMZ)
    > > --> Groupware server (Internal)
    >
    > Why do you want to split the two Postfix machines?
    >

    With professional anti-virus software it seems they listen on Port 25 (the
    ones i have checked) and only seem to be able to send to one SMTP
    server. I am not really sure what other arrangement you mean. I had
    header/body content matching on the first server just as a way of
    reducing what gets to the second postfix server, which will be doing
    more intensive work, such as checking for viruses in attachments, etc.

    Of course, this is all based on my non-existent statistics on performance
    issues...

    cheers,

    adrian

    > --
    > Ralf Hildebrandt (Im Auftrag des Referat V A) Ralf.Hildebrandtcharite.de
    > Charite Campus Virchow-Klinikum Tel. +49 (0)30-450 570-155
    > Referat V A - Kommunikationsnetze - Fax. +49 (0)30-450 570-916
    > Al Gore invented the Internet, Bill Gates deployed it. That's their
    > respective stories, anyways
    >
    > -
    > To unsubscribe, send mail to majordomopostfix.org with content
    > (not subject): unsubscribe postfix-users

    -
    To unsubscribe, send mail to majordomopostfix.org with content
    (not subject): unsubscribe postfix-users