OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Postfix configuration problems.

From: Pieterjan Heyse (pieterjan.heysescheppers-wetteren.be)
Date: Wed May 24 2006 - 05:09:18 CDT


Hi Folks,

Sorry for this resend, I hit send way too early...

I'm having doubts on whether or not our postfix server is setup
correctly. I'll start by saying that the server is functioning ok, but
I have a question regarding the smtpd_recipient_restrictions and the
relay users.

when I check my logs with this config, I see that a lot of incoming
messages (from remote users to virtual local users) are rejected
(warned). I would love to see them accepted, so I can change my
default policy to reject.

Is this sensible and can someone point me out why postfix doesn't find
my virtual users , but does deliver correctly ?

thanks.

Some config thingys for reference:

smtpd_recipient_restrictions =
permit_mynetworks
reject_non_fqdn_recipient
reject_non_fqdn_sender
reject_unknown_sender_domain
reject_unknown_recipient_domain
check_sender_access hash:/etc/postfix/sender_access
check_recipient_access hash:/etc/postfix/recipient_access
reject_unauth_destination
reject_non_fqdn_hostname
reject_invalid_hostname
reject_rbl_client relays.ordb.org
reject_rbl_client bl.spamcop.net
reject_rbl_client sbl-xbl.spamhaus.org
reject_rbl_client list.dsbl.org
reject_rbl_client combined.njabl.org
reject_rbl_client cbl.abuseat.org
check_policy_service inet:127.0.0.1:60000
warn_if_reject reject

transport_maps = proxy:mysql:/etc/postfix/mysql-transport.cf
virtual_gid_maps = mysql:/etc/postfix/mysql-virtual-gid.cf
virtual_mailbox_base = /var/spool/postfix/virtual
virtual_mailbox_maps = mysql:/etc/postfix/mysql-virtual-maps.cf
virtual_uid_maps = mysql:/etc/postfix/mysql-virtual-uid.cf
mydestination = $myhostname,$transport_maps
relocated_maps = proxy:mysql:/etc/postfix/mysql-relocated.cf
local_recipient_maps = $alias_maps $virtual_mailbox_maps unix:passwd.byname

and a part of my log:

May 24 12:07:56 localhost postfix/smtpd[29807]: NOQUEUE: reject_warning: RCPT from unknown[212.35.124.72]: 554 <joris.schoonjansscheppers-wetteren.be>: Recipient address rejected: Access denied; from=<mailer.lerarendirect.belcpnet.com> to=<joris.schoonjansscheppers-wetteren.be> proto=ESMTP helo=<Lcpnos7.corp.lcpnet.com>
May 24 12:07:56 localhost postfix/smtpd[29807]: 029C651027: client=unknown[212.35.124.72]
May 24 12:07:56 localhost postfix/cleanup[29899]: 029C651027: message-id=<LCPNOS7962c73c8a7b542a1bedecb0e09b89abbLcpnos7>
May 24 12:07:56 localhost postfix/qmgr[28747]: 029C651027: from=<mailer.lerarendirect.belcpnet.com>, size=28882, nrcpt=1 (queue active)
May 24 12:07:56 localhost amavis[30325]: (30325-05) ESMTP::10024 /var/lib/amavis/amavis-20060524T120541-30325: <mailer.lerarendirect.belcpnet.com> -> <joris.schoonjansscheppers-wetteren.be> Received: SIZE=28882 from mail.ksgwl.be ([127.0.0.1]) by localhost (mail.ksgwl.be [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 30325-05 for <joris.schoonjansscheppers-wetteren.be>; Wed, 24 May 2006 12:07:56 +0200 (CEST)
May 24 12:07:56 localhost amavis[30325]: (30325-05) Checking: <mailer.lerarendirect.belcpnet.com> -> <joris.schoonjansscheppers-wetteren.be>
May 24 12:07:56 localhost postfix/smtpd[29807]: disconnect from unknown[212.35.124.72]
May 24 12:07:57 localhost amavis[30325]: (30325-05) FWD via SMTP: [127.0.0.1]:10025 <mailer.lerarendirect.belcpnet.com> -> <joris.schoonjansscheppers-wetteren.be>
May 24 12:07:57 localhost postfix/smtpd[29906]: connect from localhost[127.0.0.1]
May 24 12:07:57 localhost postfix/smtpd[29906]: 21CFF51080: client=localhost[127.0.0.1]
May 24 12:07:57 localhost postfix/cleanup[29884]: 21CFF51080: message-id=<LCPNOS7962c73c8a7b542a1bedecb0e09b89abbLcpnos7>
May 24 12:07:57 localhost postfix/qmgr[28747]: 21CFF51080: from=<mailer.lerarendirect.belcpnet.com>, size=29553, nrcpt=1 (queue active)
May 24 12:07:57 localhost postfix/smtpd[29906]: disconnect from localhost[127.0.0.1]
May 24 12:07:57 localhost postfix/virtual[29907]: 21CFF51080: to=<joris.schoonjansscheppers-wetteren.be>, relay=virtual, delay=0, status=sent (delivered to maildir)
May 24 12:07:57 localhost postfix/qmgr[28747]: 21CFF51080: removed
May 24 12:07:57 localhost amavis[30325]: (30325-05) Passed, <mailer.lerarendirect.belcpnet.com> -> <joris.schoonjansscheppers-wetteren.be>, Message-ID: <LCPNOS7962c73c8a7b542a1bedecb0e09b89abbLcpnos7>, Hits: -3.909
May 24 12:07:57 localhost postfix/smtp[29885]: 029C651027: to=<joris.schoonjansscheppers-wetteren.be>, relay=127.0.0.1[127.0.0.1], delay=2, status=sent (250 2.6.0 Ok, id=30325-05, from MTA: 250 Ok: queued as 21CFF51080)
May 24 12:07:57 localhost postfix/qmgr[28747]: 029C651027: removed

--
Pieterjan

ICT Coördintor KSGWL - Scheppersinstituut
Scheppersinstituut Wetteren
Cooppallaan 128
9230 Wetteren
Tel: 09 3692072
Fax: 09 3661348
mailto:pieterjan.heysescheppers-wetteren.be