Great Circle Associates Firewalls
(August 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: [FW1] Problems with FW-1's asmtp
From: Tycho Fruru <tycho @ netvision . be>
Organization: Netvision
Date: Fri, 29 Aug 1997 14:45:27 +0200
To: sbollini @ lightech . com . ar
Cc: "Mailing List, Firewall-1" <fw-1-mailinglist @ us . checkpoint . com>, "firewalls @ GreatCircle . COM" <firewalls @ GreatCircle . COM>
References: <34029651 . E6FC3B88 @ lightech . com . ar>

Sergio Bollini wrote:

> For outbound mail, I haven't an external mail relay; instead, asmtpd
> must be able to resolve MX registers by himself and establish a smtp
> connection directly with the mail's destination. In page 86 of "Managing
> FireWall-1 Using the OpenLook GUI", it says that leaving empty "Mail
> Server" field in SMTP resource specification window and "default_server"
> field in $FWDIR/conf/smtp.conf file "then mail is forwarded to its
> original destination". When I defined the resource for outbound mail, I
> left blank both fields (the intended effect of this is forcing asmtp to
> resolve MX); then when the firewall receives an outgoing mail, it fails
> to retransmit it to the outside saying that cannot connect to the final
> MTA.

Yes.  The internal machine (which is sending the mail) should contact the
external MX host immediately.  The SMTP proxy works in a transparant
fashion.  It does (AFAIK) not do any MX lookups.  It's just a
store-and-forward thingie.

Best regards,
Tycho

--
                      | ir. Tycho Fruru
                      | Sr. Security Engineer
                      |
             NetVision nv
       tycho @
 netvision .
 be
  http://www.netvision.be
                      |
                      | T. +32-(0)16-31.00.15
                      | F. +32-(0)16-31.00.29





References:
Indexed By Date Previous: Re: NetRanger
From: Kevin McPeake <cowboy @ home . byelex . nl>
Next: Re: IP Addressing strategy-URGENT
From: azeem @ sriven . scs . co . in
Indexed By Thread Previous: Re: Problems with FW-1's asmtp
From: Denis Golubev <dlg @ jet . msk . su>
Next: CVP Question
From: Alessandro Jannuzzi <jannuzzi @ csn . com . br>

Google
 
Search Internet Search www.greatcircle.com