| |||||||||||||||||||||||||||||||
|
> 9:32am Victor Duchovni said: > >> On Wed, Oct 24, 2007 at 06:27:08AM -0700, Curtis Doty wrote: >> >>> No, I meant that postfix wasn't listening on the tunnel interface, which >>> is where the clients will try to connect/relay. And if I add the >>> tunnel's >>> IP address to inet_interfaces, postfix will refuse to start if the >>> tunnel >>> is down. >> >> If Postfix is listening on "all" interfaces, the tunnel will be included >> in the 0.0.0.0 listening socket. Otherwise you are out of luck. If some >> interfaces need to not be exposed, use the hosts firewall software if >> any to block the interfaces that should be excluded. >> > > Gotcha, thanks. I will disable all use of inet_interfaces and use other > non-postfix means to restrict access to the "dangerous" interfaces. > > ../C > If the tunnel's address is static then add the IP address to lo/eth0 in a script when lo/eth0 comes up. The address will exist for postfix and once the interface actually comes up, then voila.
| ||||||||||||||||||||||||||||||
© 2004-2008 readlist.com