relaying - mynetworks

messerle

New Member
Jan 10, 2006
7
0
1
Austria
www.messerle.at
Hi,

A generally question about relaying - inbound and outbound mail ...

Am i right, that everybody who can connect to the proxmox server at port 26 is able to relay mails? If so, not really a problem more a question of the firewall settings ...

but

is there an other possibility to allow a specified host to relay thru the proxmox server?

I tried to change the 'mynetworks' parameter in the postfix config but it doesn't seems to work ...

Background: I have a webserver in my dmz (same subnet than the proxmox test installation) running, which sends eMails to different (external) recipients. programmed with asp pages

-> so: is there a possibility to let my web server send these emails outbound without reprogramming the whole website for changing the ports?

t'x and sorry for my English
chris
 
messerle said:
Hi,

A generally question about relaying - inbound and outbound mail ...

Am i right, that everybody who can connect to the proxmox server at port 26 is able to relay mails? If so, not really a problem more a question of the firewall settings ...

but

is there an other possibility to allow a specified host to relay thru the proxmox server?

I tried to change the 'mynetworks' parameter in the postfix config but it doesn't seems to work ...

Background: I have a webserver in my dmz (same subnet than the proxmox test installation) running, which sends eMails to different (external) recipients. programmed with asp pages

-> so: is there a possibility to let my web server send these emails outbound without reprogramming the whole website for changing the ports?

t'x and sorry for my English
chris

hi chris,

you should change the internal and external smtp ports.

1. on your firewall, change incoming 25 smtp port to 26 and send this to your proxmox
2. on your proxmox, you have to change external port to 26, internal to 25 (under mail proxy configuration)
3. so your webserver can communicate on port 25 with proxmox.
4. your webserver is in the same subnet, so relaying is automatically allowed.

regards,
martin
 
t'x martin, but well ... doesn't really solve my problem because i use offical ip's in my dmz so it's not just a portforwarding on my fw which i can manipulate ... external mailers will 'directly' connect to the proxmox server ...

conclusion concerning my question(s):
relaying is allowed for clients which are able to connect to 'port 26' (outgoing smtp port) on te proxmox server AND which are defined in 'mynetworks' (usually the proxmox server net and the internal mail server's ip) ... RIGHT?

t'x
chris
 
messerle said:
t'x martin, but well ... doesn't really solve my problem because i use offical ip's in my dmz so it's not just a portforwarding on my fw which i can manipulate ... external mailers will 'directly' connect to the proxmox server ...

hi,
why can´t you redirect the smtp (DNAT) traffic? this is independent if you use public ip addresses or not.

regards,
martin
 
messerle said:
conclusion concerning my question(s):
relaying is allowed for clients which are able to connect to 'port 26' (outgoing smtp port) on te proxmox server AND which are defined in 'mynetworks' (usually the proxmox server net and the internal mail server's ip) ... RIGHT?
chris

Yes, but 'mynetworks' also includes all defined transport hosts.

- Dietmar
 
hi, wenn i edit the main.cf file (of postfix) to add a internal host in 'my networks' proxmox will relay mail from this internal host....thats ok.
but when i visit the admin interface the main.cf will be 'reseted', after that i can't ralay from the internal host...but we need this....

is there a solution?

thx
christian
 
Version 1.3 will have an extra configuration page to add trusted hosts.

Temorary hack for V1.2: edit the template

/var/lib/proxmox/templates/main.cf.in

Best Regards,

Dietmar
 
looks fine, just run

proxconfig -s

to sync the configuratin and restart postfix with:

/etc/init.d/postfix restart

to aktivate your changes.

- Dietmar
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!