6 msgTemporary blacklisting of hosts that send email...
9 msgdefer and deferred
3 msgHow to make postfix log complete 'From' address?

inet_interfaces and dynamic interfaces
\ Curtis Doty (23 Oct 2007)
. \ Noel Jones (23 Oct 2007)
. . \ Curtis Doty (24 Oct 2007)
. . . \ Victor Duchovni (24 Oct 2007)
. . . . \ Curtis Doty (24 Oct 2007)
. . . . . \ Robert Vangel (25 Oct 2007)

2 msgWhether to set masquerade_classes
3 msgTransport map? or.. sending mail somewhere othe...
3 msgLarge scale Postfix/Cyrus email system for 100,...
4 msgCollecting spam via RBLs?
4 msgqueue not moving fast
1 msgRE: What is a Postfix policy server? - Thanks
4 msggateway between the world and an internal mails...
2 msgrbl
2 msghigh-priority queue?
2 msgPostgray + Postfix Recipient Access
3 msg'Illegal seek' errors
5 msgPostfix + CyrusSASL on Centos
5 msgpostfix 2.2.8 losing emails
4 msg'Recipient address rejected: Policy' - What Pol...
7 msgPostfix and RDNS
1 msgLDAP and mail expansion while sending it.
Subject:Re: inet_interfaces and dynamic interfaces
Group:Postfix-users
From:Robert Vangel
Date:25 Oct 2007


 
Curtis Doty wrote:
> 9:32am Victor Duchovni said:
>
>> On Wed, Oct 24, 2007 at 06:27:08AM -0700, Curtis Doty wrote:
>>
>>> No, I meant that postfix wasn't listening on the tunnel interface, which
>>> is where the clients will try to connect/relay. And if I add the
>>> tunnel's
>>> IP address to inet_interfaces, postfix will refuse to start if the
>>> tunnel
>>> is down.
>>
>> If Postfix is listening on "all" interfaces, the tunnel will be included
>> in the 0.0.0.0 listening socket. Otherwise you are out of luck. If some
>> interfaces need to not be exposed, use the hosts firewall software if
>> any to block the interfaces that should be excluded.
>>
>
> Gotcha, thanks. I will disable all use of inet_interfaces and use other
> non-postfix means to restrict access to the "dangerous" interfaces.
>
> ../C
>

If the tunnel's address is static then add the IP address to lo/eth0 in
a script when lo/eth0 comes up. The address will exist for postfix and
once the interface actually comes up, then voila.


© 2004-2008 readlist.com