[clue-tech] postfix

Adam bultman adamb at glaven.org
Sat May 20 16:14:32 MDT 2006


Jeff Cann wrote:
> I've read the postfix docs and I'm still unclear on the exact procedure.
>
> Here's what I currently have and this is allowing users to send if 
> they are on the same network as the postfix server.  It also does not 
> allow random spammers to connect.  But, it does not allow legitimate 
> users off our postfix network to send email.
>
> # sasl for SMTP authorization
> smtpd_sasl_auth_enable = yes
> broken_sasl_auth_clients = yes
> smtpd_sasl_security_options = noanonymous
> smtpd_recipient_restrictions = permit_mynetworks 
> reject_unauth_destination
> smtpd_client_restrictions = permit_sasl_authenticated
>
> How can I setup my postfix SMTP server to allow legitimate remote 
> users to send email?
Are you asking for a HOWTO, or are you simply asking for methods of 
selectively permitting relaying?

Methods:
1. IP based - add individual networks or IPs to mynetworks
2. Pop/Imap before SMTP:  Accessing and authenticating with the POP/IMAP 
server will add the IP address of the client for a number of minutes (15 
minutes, for example).
3. SMTP AUTH. (Add SASL for increased fun!)

If you're asking for a HOWTO, here's one:
http://postfix.state-of-mind.de/patrick.koetter/smtpauth/

What distribution are you running? If you're running a debian based box, 
I'll fiddle with my little server here, and then let you know.  I've 
been meaning to open up my postfix server here to the world, but I lack 
the impetus. 

Adam




More information about the clue-tech mailing list