OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: Allow all types of Relay for a Hotspot Provider..

From: Lee Quince (Lee.Quinceiqunity.com)
Date: Tue May 13 2008 - 03:55:25 CDT


Stefan Förster wrote:
> * Lee Quince <Lee.Quinceiqunity.com> wrote:
>
>> I am looking to do the following..
>>
>> Be able to relay on the Basis of LocalNetwork as the sole accept.
>>
>
> You can set mynetworks to an appropriate setting and then use the
> "permit_mynetworks" restriction in smptd_recipient_restrictions.
>
>
>
No problem here I understand this part.
>> For none authorised SMTP client's we just redirect port 25 at the
>> firewall level to the postfix server, this then causes a problem with
>> the AUTH'd clients as the server does not know the username / password
>> they are trying to use.. Is there a way to get the server to accept any
>> combination..??
>>
>
> Your firewall can intercept encrypted traffic and reroute it? I don't
> understand what you are trying to accomplish.
>
Ok say your ISP is force9.net, your staying in a hotel and you want to
send email without changing your SMTP setting's. force9 servers will
only allow a relay for there connected network. Hence while you are in
the hotel and using our network relay is denied. To get around this we
basically redirect port 25 TCP using NAT to our postfix server's, (we do
some grey listing and max messages, per min, ClamAV etc to protect
ourselves.)

The problem we have is if the client's ISP normally allows there
customer to send via there SMTP server on port 25 TCP (the one located
at the ISP) using SMTP with AUTH, this could be plain, cleartext or
TLS.. We are redirecting the traffic already to ourselves.. So I need to
if possible ignore the AUTH from the client on our network and allow relay.

Regards

Lee
>
> Cheers
> Stefan
>

--

Lee Quince
Managing Technical Director
iQunity Ltd
Undivided Attention
mobile: 07970 070 806
fax: 08703 835 661

_Internet Email Confidentiality Notice:__ _
This message contains confidential information. If you are not the
addressee indicated in this message, you may not copy or deliver it to
anyone. In such case, you should destroy this message and kindly notify
us by reply email