Great Circle Associates Firewalls
(August 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Mail gateway: how?
From: "Andrew T. Robinson" <atr @ maine . net>
Date: Wed, 17 Aug 94 22:42:56 EST
To: Firewalls mailing list <firewalls @ greatcircle . COM>

Given the following configuration:

OUTSIDE <---> BASTION <------+-----------(LAN)-------+----------
                             |                       |
                         MAIL HOST               OTHER HOSTS

Firewall is set up with split DNS (bastion advertises only its own name/address;
internal DNS maps LAN hosts;  resolv.conf on bastion points to internal, which 
thinks the bastion is a root server and also uses FORWARDERS to the bastion DNS 
for resolving external names).

What I want:   

1. All mail coming in to the domain goes to mail host (this almost 
works--sendmail complains about local configuration error, which sendmail books
say nothing about).

2. All mail going OUT needs to go through the BASTION host since internal 
machines don't have connectivity to the Internet except via bastion proxies.. 
The original plan was for everything to go to the MAIL HOST and then to the
BASTION host, but I'd settle for getting all outgoing mail to the BASTION 
host at this point.

Please reply to me directly, as I know this is a FAQ;  I've read through my 
4000+ firewalls posting archive but haven't found anything specific enough to be
useful;  For reference I'm running BSDI BSD/386 UNIX v1.1.

Andy


Indexed By Date Previous: Re: Security of Appletalk and Dial back modems
From: blu @ jericho . mc . com (Brian Utterback)
Next: Re: breakin' to log
From: Paul Joslin (Sverdrup) <pjoslin @ mbvlab . wpafb . af . mil>
Indexed By Thread Previous: Re: Security of Appletalk and Dial back modems
From: bret @ real . com (Bret McDanel)
Next: Security
From: "Kenneth Aveirls" <KAVEIRLS @ PHSATL . SSW . DHHS . GOV>

Google
 
Search Internet Search www.greatcircle.com