5 msgpostconf not displaying all options
3 msgempty_address_recipient not mapped by virtual o...

stop smtp from anyone unless sasl auth?
\ Jordan Tardif (23 Jul 2007)
. \ Justin McAleer (23 Jul 2007)
. . \ Victor Duchovni (23 Jul 2007)
. . \ Jordan Tardif (23 Jul 2007)
. . . \ Duane Hill (23 Jul 2007)

2 msg'piped' aliases & DSNs
12 msgStrange From: in headers
5 msgMail - Access Denied
4 msgqpsmtpd support service for postfix
39 msgpix workaround broken?
2 msgX-Original-To after bcc contains wrong address
8 msg/usr/lib/sendmail delivery status/message id's ...
23 msgRecommended Filesystems?
8 msgMail going to backup server instead main server
3 msgoutgoing rate control
5 msgmail forwarding loop: how do I prevent this?
5 msgServer relaying existing virtual mailbox
1 msghow can I rewrite the Mail From
3 msgConstant connections from user unknown sending ...
2 msgsporadic deferrals
8 msgtransport_maps: different behavior if discard o...
4 msgAddress verification questions
Subject:Re: stop smtp from anyone unless sasl auth?
Group:Postfix-users
From:Duane Hill
Date:23 Jul 2007


 
On Mon, 23 Jul 2007 at 12:37 -0700, jordan confabulated:

> That would make sense.. for some reason i think ive tried that though and it
> caused problems. I shall try again and see what i come up with.
>

This is what I have in an instance of Postfix running for outbound sending
for our customers:

smtpd_recipient_restrictions =
permit_mynetworks,
permit_sasl_authenticated,
reject

It works like a charm. If a message is not coming from $mynetworks or an
authenticated client, the message gets rejected.

>
> On Mon, 23 Jul 2007, Justin McAleer wrote:
>
>> Jordan Tardif wrote:
>>> Basicly I want to make it so only sasl auth'd users can send through A
>>> record machines.. As the config is right now non-local ip's can connect to
>>> the machine and send mail to a local domain without having to auth at
>>> all.. I was pretty sure that this stopped that but i guess im wrong..
>>>
>>> smtpd_recipient_restrictions =
>>> reject_unauth_pipelining reject_non_fqdn_sender
>>> reject_non_fqdn_recipient check_policy_service inet:10.3.19.237:10031
>>> permit_sasl_authenticated
>>> reject_unauth_destination
>>> permit
>>>
>>
>> I believe what you want is to simply change that permit to reject.
>>
>>> This is not jut email from $mynetworks but from any ip. Anyone know any
>>> way I can stop mail being sent by anyone that is not sasl authd? Here is
>>> my full config..
>>>
>>>
>>
>>
>

-------
_|_
(_| |


© 2004-2008 readlist.com