Great Circle Associates Firewalls
(July 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: proxying characteristics of smtp
From: harker @ harker . com (Robert Harker)
Date: Sat, 27 Jul 1996 11:59:12 GMT
To: mjd @ soi . city . ac . uk
Cc: firewalls @ GreatCircle . COM

The cheap way to do this is with a cheap 386 or 486, Linux or FreeBSD,
TIS FWTK's smap daemon sendmail setup as a firewall relay.

As to using Exchange as an SMTP mail relay, no can do.  The way Exchange
deals with inbound SMTP mail is by looking up the destination address in
its "container" user address databases.  If the address does not exist
in an Exchange container, then Exchange bounces the message as an unknown
address.

On a related note Exchange also has no ability to rewrite addresses in a
general way.  Any different variant of an address you might want to handle,
such as user%host @
 domain, has to be entered into an Exchange container on
a per user basis (although it seems to be possible create the same variant
for all users in a container).  It is true, try sending mail to:
	yourid%yourdomain @
 microsoft .
 com
A perfectly valid RFC 822 email address.  Looks like you still need sendmail
or some other general purpose routing software that can do address rewriting
to sanitize the hodge podge of addresses that a real Internet site receives.

I suspect that Micro$oft's attitude towards SMTP on a firewall is to either
run a SMTP packet forwarding application (inverse proxy?) on the firewall
to forward all SMTP TCP packets from the outside to an internal Exchange
server, or since NT's and Exchange's security are so superior (:-) to
anything else just run your Exchange SMTP connectors (mailers in sendmail
parlance) directly on the firewall itself.

Hope this helps
RLH

 > For info about our Sendmail Made Simple and Advanced Sendmail classes and <
 >  a schedule of dates and locations, please send email to info @
 harker .
 com  <

Robert Harker						Harker Systems
Sendmail and TCP/IP Network Training			1180 Hester Ave
Network and Sysadmin Consulting				San Jose, CA 95126
harker @
 harker .
 com					408-295-9432


Indexed By Date Previous: Pident/Tap
From: Dave Horsfall <dave @ fgh . oz . au>
Next: Re: Catapult
From: John Betts <johnb @ aztec . co . za>
Indexed By Thread Previous: proxying characteristics of smtp
From: Mike Dilworth <mjd @ soi . city . ac . uk>
Next: RE: proxying characteristics of smtp
From: Mike Dilworth <mjd @ soi . city . ac . uk>

Google
 
Search Internet Search www.greatcircle.com