|
|||||||||||
|
Q about mail proxy servers and setups
From: Michael Scheidell <scheidell(at)secnap.net>
Date: Sun Sep 23 2007 - 13:50:43 EDT
However, sometimes, client, security and company policy needs outweigh
logic.
#1, SPF. SPF helo, SENDERID For Amavisd/others that use p0f, all we get is signature of the proxy. Smtp ratelimiting, greyisting, even recipient verification break. You can't drop the SMTP session when the sender sends you an email with a bad address, the proxy has already accepted it. You can't use 4xx errors in your policy server to do greylisting on policy blacklisting because you are sending the 4xx error to the proxy. On amavis, if we use MY_NETS policy, and we put the proxy ip in the 'localnets', it will spam the spam and virus contact address on every email from the 'local network'. If you don't put it in there, it breaks some of the things I mentioned above.
Anything else I missed?
-- Michael Scheidell, CTO Office: 561-999-5000 x 1259 Direct: 561-939-7259 Join SECNAP at SecureWorld Detroit 9-10 http://www.secnap.com/events for free and discounted seminar tickets _________________________________________________________________________ This email has been scanned and certified safe by SpammerTrap(tm). For Information please see http://www.spammertrap.com _________________________________________________________________________Received on Sun Sep 23 13:52:28 2007 This archive was generated by hypermail 2.1.8 : Sat Oct 27 2007 - 11:05:44 EDT |
||||||||||
|
|||||||||||