2 msgRemote backup Postfix server
7 msgchose interface for outgoing mail
2 msgIllegal address syntax ... in MAIL command: <...
1 msgMail Infrastructure and Zertificon
1 msgsasl password
6 msgpostfix TLS (configuration/user) problem
7 msgVirtual Alias Domain
3 msgcopy of email
2 msgDNS Caching?
5 msgUsing mysql for mynetworks
5 msgBlocking e-mail from a domain, to a particular ...
5 msgprevent open relay
15 msgcannot get mail from outside to my smtp server
6 msgError connecting Postfix to LDAP
5 msgConfig ok for TLS/SASL/Client Cert via port 587?

mail flow architecture
\ Barbara M. (12 Mar 2008)
. \ Ralf Hildebrandt (12 Mar 2008)
. . \ Barbara M. (12 Mar 2008)
. . . \ Ralf Hildebrandt (12 Mar 2008)
. . . . \ Brian Evans (12 Mar 2008)
. . . \ Jorey Bump (12 Mar 2008)
. \ mouss (12 Mar 2008)

3 msgvirtual forward + deliver
1 msgRe: RESOLVED: Using Canonical Maps as an Overri...
14 msgdual mail server
3 msghow to specify different outgoing IP
Subject:mail flow architecture
Group:Postfix-users
From:Barbara M.
Date:12 Mar 2008


 

This is the situation:


Internet
|
|
| (a.b.c.d)
FW
| (192.168.1.1)
|
|
SWITCH (DMZ)
|
|
|-SMTP-IN (192.168.1.2) (Postfix 2.1.x, spamassassin, clamav, sqlgrey)
|
|-MAIL (192.168.1.3) (Postfix 2.1.x, dovecot, procmail)
|
|-SMTP-OUT (192.168.1.4) (Postfix 2.1.x, spamassassin, clamav)


Some hundred domains; Mails come in via the public IP a.b.c.d that is
forwarded to the internal box SMTP-IN where if they pass sqlgrey are
scanned for virus/spam and forwarded to MAIL (only header are modified).
Outgoing mail go via SMTP-OUT.

All ok until some weeks ago when we start having daily mail stats like
this:

Postfix log summaries for Mar 10

Grand Totals
------------
messages

58803 received
59638 delivered
2 forwarded
773 deferred (5920 deferrals)
5813 bounced
1396k rejected (95%)
0 reject warnings
0 held
0 discarded (0%)

5327m bytes received
5797m bytes delivered
9682 senders
7670 sending hosts/domains
6292 recipients
2025 recipient hosts/domains


We have over 1 million mails/day. :-( 95% rejected from greylisting.
Logs grow very rapidly ... :-(

I think a good idea can be using RBL (disabled in the past because they
create various problems).

Our needs are:
- some hints for using RBL "safely" (great chances of experiments in
production box).
- hints/links/config-examples to build new box that replace our SMTP-IN


Regards, B.




© 2004-2008 readlist.com