Great Circle Associates Firewalls
(January 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Re[2]: Attn. Sendmail gurus!
From: mshaver @ schoolnet . carleton . ca (Mike Shaver)
Date: Fri, 20 Jan 1995 20:14:31 -0500 (EST)
To: brian @ imcon . ilinx . com
Cc: firewalls @ greatcircle . com
In-reply-to: <m0rVS2u-000K0NC @ ilinx . com> from "brian @ imcon . ilinx . com" at Jan 20, 95 02:44:13 pm

brian @
 imcon .
 ilinx .
 com mumbled something vague about:
> 
> from the quill of mshaver @
 schoolnet .
 carleton .
 ca (Mike Shaver)
> > Rob Sansom mumbled something vague about:
> > > I've been having problems with one of my internal hosts name appearing in 
> > > mail headers.  See below:
> > 
> > I'd say that it's a tricky thing, since in theory, all machines that process
> > a message are *supposed* to add the Received: header.
> > I suppose you could hack the offending sendmail to not add the Received
> > line, but I'd keep a "standard" copy around in case something breaks.
> Is it really tricky??  I've yet to dig in, but I've been meaning to make a
> "firewall sendmail.cf" file that strips out all the Received: headers and puts
> only the one from the firewall in, and rewrite any headers which get built as
> the mail passes from inside machines to the firewall.  Will I have a hard time
> doing this??  I'm not so sure I will.
Oh, you could easily write a perl script to do it, but that wasn't my
point... the standards that the Internet lives and dies by specify that all
machines processing mail add their little stamp to it, to aid in mail
debugging.

I'm not so certain it's a good idea for firewalls to rewrite the headers
wholesale, and lose that valuable debugging information.  I think a better
solution is the use of fake names for mail headers, which are totally
unrelated to the DNS names (internal and external).

Mike

Indexed By Date Previous: Re: FTP through firewall
From: Phil Trubey <phil @ netpart . com>
Next: Re: Firewall Product List
From: Steve Norton <steve @ interaccess . com>
Indexed By Thread Previous: Re: Attn. Sendmail gurus!
From: mshaver @ schoolnet . carleton . ca (Mike Shaver)
Next: Re: Attn. Sendmail gurus!
From: "Henning Stams" <hstams @ k . mup . de>

Google
 
Search Internet Search www.greatcircle.com