Re: Current status?
- From: helbig@xxxxxxxxxxxxxxxxxxxxxxxx (Phillip Helbig---remove CLOTHES to reply)
- Date: Sat, 6 Sep 2008 10:24:56 +0000 (UTC)
In article <g9sigp$gs$1@xxxxxxxxxxxxxxxxx>, david20@xxxxxxxxxxxxxxxx
writes:
All mail I send anywhere via TCPIP goes through the host specified as
the alternate gateway. The highest-priority MX record is the WAN
address of my LAN, which gets forwarded to the cluster alias.
On my ROUTER, of course, not on my LAN.
So your alternate gateway and MX record host are your designated MTAs which
should be allowed to communicate with the outside world over port 25.
Right.
Any other systems on your internal network which wish to send mail out should
send out either directly or indirectly through the same alternate gateway.
That's what they do. To the outside world, it looks like everything
comes from the WAN address of the router.
Any mail for users on any other internal mail system should receive mail by it
first being passed to the MX system which then forwards it onto the internal
system.
Internal mail is directly within the cluster, i.e. no TCPIP.
Hence the other internal systems do not require to open connections
directly to port 25 on arbitrary external systems or to have arbitrary
external systems connecting directly to port 25 on them. Your firewall can
therefore block those other internal systems from attempting such port 25
connections.
The outside world can see only the WAN address, and that goes to the
cluster alias on the LAN. All systems have the same SMTP configuration,
in particular the same alternate gateway.
(You mention the WAN address of your LAN which suggests that you probably have
an internal network which is using dynamic NAT.
Right, NAT and PAT.
Hence NAT is probably taking
care of stopping direct external connections to your other internal systems on
port 25 anyway.)
Right.
.
- References:
- Re: [RBL] Current status?
- From: John E. Malmberg
- Re: [RBL] Current status?
- From: John E. Malmberg
- Re: [RBL] Current status?
- From: Bob Koehler
- Re: [RBL] Current status?
- From: Bill Gunshannon
- Re: Current status?
- From: johnwallace4
- Re: Current status?
- From: Bill Gunshannon
- Re: Current status?
- From: Phillip Helbig---remove CLOTHES to reply
- Re: [RBL] Current status?
- Prev by Date: Yes, WASD works with CrossDomain.xml (was: Google Chrome, VMS, and Tier3)
- Next by Date: Re: OT: Carly speeks at convetion
- Previous by thread: Re: Current status?
- Next by thread: Re: Current status?
- Index(es):
Relevant Pages
|