Networking Forums

Networking Forums > Computer Networking > Windows Networking > SMTP & Firewall question....

Reply
Thread Tools Display Modes

SMTP & Firewall question....

 
 
Aaron Anderson
Guest
Posts: n/a

 
      03-17-2006, 01:14 AM
I'm not sure if this is in the right place. If anyone can recommend a better
newsgroup for networking and related info, please advise.


I have a simple question.

I host my own email server. MX records direct the mail through a third party
spam filtering service (mxlogic.com)

It is my understanding that I should only allow incoming connections to my
server from their posted IP addresses ( 66.179.26.128/26)

If I change the ACL on my firewall, then no clients are able to send
email...

Does this make sense? I think I'm missing a piece of the puzzle....


 
Reply With Quote
 
 
 
 
Neteng
Guest
Posts: n/a

 
      03-17-2006, 01:14 PM
Can you post your ACL in and out?

"Aaron Anderson" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> I'm not sure if this is in the right place. If anyone can recommend a

better
> newsgroup for networking and related info, please advise.
>
>
> I have a simple question.
>
> I host my own email server. MX records direct the mail through a third

party
> spam filtering service (mxlogic.com)
>
> It is my understanding that I should only allow incoming connections to my
> server from their posted IP addresses ( 66.179.26.128/26)
>
> If I change the ACL on my firewall, then no clients are able to send
> email...
>
> Does this make sense? I think I'm missing a piece of the puzzle....
>
>



 
Reply With Quote
 
Aaron Anderson
Guest
Posts: n/a

 
      03-17-2006, 02:06 PM
Not easily. it's a sonicwall firewall.

Basically if I set the SMTP server to only accept incoming traffic from mx
logic (66.179.26.128 - 66.179.26.190) then I wouldn't be able to send mail
from my personal computer, because my external IP wouldn't be in the rule...


"Neteng" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> Can you post your ACL in and out?
>
> "Aaron Anderson" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed)...
>> I'm not sure if this is in the right place. If anyone can recommend a

> better
>> newsgroup for networking and related info, please advise.
>>
>>
>> I have a simple question.
>>
>> I host my own email server. MX records direct the mail through a third

> party
>> spam filtering service (mxlogic.com)
>>
>> It is my understanding that I should only allow incoming connections to
>> my
>> server from their posted IP addresses ( 66.179.26.128/26)
>>
>> If I change the ACL on my firewall, then no clients are able to send
>> email...
>>
>> Does this make sense? I think I'm missing a piece of the puzzle....
>>
>>

>
>



 
Reply With Quote
 
Neteng
Guest
Posts: n/a

 
      03-17-2006, 04:34 PM
Do you have two ACL's, one inbound and one outbound? Email going out should
be going through your mail server and that is the only box that should need
TCP 25 going out.

"Aaron Anderson" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> Not easily. it's a sonicwall firewall.
>
> Basically if I set the SMTP server to only accept incoming traffic from mx
> logic (66.179.26.128 - 66.179.26.190) then I wouldn't be able to send

mail
> from my personal computer, because my external IP wouldn't be in the

rule...
>
>
> "Neteng" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed)...
> > Can you post your ACL in and out?
> >
> > "Aaron Anderson" <(E-Mail Removed)> wrote in message
> > news:(E-Mail Removed)...
> >> I'm not sure if this is in the right place. If anyone can recommend a

> > better
> >> newsgroup for networking and related info, please advise.
> >>
> >>
> >> I have a simple question.
> >>
> >> I host my own email server. MX records direct the mail through a third

> > party
> >> spam filtering service (mxlogic.com)
> >>
> >> It is my understanding that I should only allow incoming connections to
> >> my
> >> server from their posted IP addresses ( 66.179.26.128/26)
> >>
> >> If I change the ACL on my firewall, then no clients are able to send
> >> email...
> >>
> >> Does this make sense? I think I'm missing a piece of the puzzle....
> >>
> >>

> >
> >

>
>



 
Reply With Quote
 
Aaron Anderson
Guest
Posts: n/a

 
      03-17-2006, 04:47 PM
I'm sitting at home w/ Outlook... when outlooks contacts my mail
server......


errr, for some reason i keep thinking that when i send email, it's going
straight to my server in the office. it's not, it should go through the
third party provider...


let me poke around.



"Neteng" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> Do you have two ACL's, one inbound and one outbound? Email going out
> should
> be going through your mail server and that is the only box that should
> need
> TCP 25 going out.
>
> "Aaron Anderson" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed)...
>> Not easily. it's a sonicwall firewall.
>>
>> Basically if I set the SMTP server to only accept incoming traffic from
>> mx
>> logic (66.179.26.128 - 66.179.26.190) then I wouldn't be able to send

> mail
>> from my personal computer, because my external IP wouldn't be in the

> rule...
>>
>>
>> "Neteng" <(E-Mail Removed)> wrote in message
>> news:(E-Mail Removed)...
>> > Can you post your ACL in and out?
>> >
>> > "Aaron Anderson" <(E-Mail Removed)> wrote in message
>> > news:(E-Mail Removed)...
>> >> I'm not sure if this is in the right place. If anyone can recommend a
>> > better
>> >> newsgroup for networking and related info, please advise.
>> >>
>> >>
>> >> I have a simple question.
>> >>
>> >> I host my own email server. MX records direct the mail through a third
>> > party
>> >> spam filtering service (mxlogic.com)
>> >>
>> >> It is my understanding that I should only allow incoming connections
>> >> to
>> >> my
>> >> server from their posted IP addresses ( 66.179.26.128/26)
>> >>
>> >> If I change the ACL on my firewall, then no clients are able to send
>> >> email...
>> >>
>> >> Does this make sense? I think I'm missing a piece of the puzzle....
>> >>
>> >>
>> >
>> >

>>
>>

>
>



 
Reply With Quote
 
Aaron Anderson
Guest
Posts: n/a

 
      03-17-2006, 04:53 PM
ignore my last post.

If i'm at home, and send an email, I will need access to port 25, on my
mailserver.

if i restrict all incoming traffic to that of mxlogic's servers, how will
the mail that I send get anywhere?

at this point, i have no outbound restrictions on the servers.




"Neteng" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> Do you have two ACL's, one inbound and one outbound? Email going out
> should
> be going through your mail server and that is the only box that should
> need
> TCP 25 going out.
>
> "Aaron Anderson" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed)...
>> Not easily. it's a sonicwall firewall.
>>
>> Basically if I set the SMTP server to only accept incoming traffic from
>> mx
>> logic (66.179.26.128 - 66.179.26.190) then I wouldn't be able to send

> mail
>> from my personal computer, because my external IP wouldn't be in the

> rule...
>>
>>
>> "Neteng" <(E-Mail Removed)> wrote in message
>> news:(E-Mail Removed)...
>> > Can you post your ACL in and out?
>> >
>> > "Aaron Anderson" <(E-Mail Removed)> wrote in message
>> > news:(E-Mail Removed)...
>> >> I'm not sure if this is in the right place. If anyone can recommend a
>> > better
>> >> newsgroup for networking and related info, please advise.
>> >>
>> >>
>> >> I have a simple question.
>> >>
>> >> I host my own email server. MX records direct the mail through a third
>> > party
>> >> spam filtering service (mxlogic.com)
>> >>
>> >> It is my understanding that I should only allow incoming connections
>> >> to
>> >> my
>> >> server from their posted IP addresses ( 66.179.26.128/26)
>> >>
>> >> If I change the ACL on my firewall, then no clients are able to send
>> >> email...
>> >>
>> >> Does this make sense? I think I'm missing a piece of the puzzle....
>> >>
>> >>
>> >
>> >

>>
>>

>
>



 
Reply With Quote
 
Neteng
Guest
Posts: n/a

 
      03-17-2006, 05:43 PM
Your mail server is in your private network correct? Are you trying to send
mail when your outside your network (going through your mail server though)?
When you are on your network and you send an email, the communication
between you and your mail server never hits the firewall so it is not being
blocked there. If you have an ACL on the inside/trusted interface of your
firewall, you need to allow your mail server IP address out to anywhere on
TCP port 25. This allows your mail server to send emails out to the world.
Incoming should be what you had stated earlier, from 66.179.26.128 -
66.179.26.190 only, again on TCP port 25 (unless they use a different port).



"Aaron Anderson" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> ignore my last post.
>
> If i'm at home, and send an email, I will need access to port 25, on my
> mailserver.
>
> if i restrict all incoming traffic to that of mxlogic's servers, how will
> the mail that I send get anywhere?
>
> at this point, i have no outbound restrictions on the servers.
>
>
>
>
> "Neteng" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed)...
> > Do you have two ACL's, one inbound and one outbound? Email going out
> > should
> > be going through your mail server and that is the only box that should
> > need
> > TCP 25 going out.
> >
> > "Aaron Anderson" <(E-Mail Removed)> wrote in message
> > news:(E-Mail Removed)...
> >> Not easily. it's a sonicwall firewall.
> >>
> >> Basically if I set the SMTP server to only accept incoming traffic from
> >> mx
> >> logic (66.179.26.128 - 66.179.26.190) then I wouldn't be able to send

> > mail
> >> from my personal computer, because my external IP wouldn't be in the

> > rule...
> >>
> >>
> >> "Neteng" <(E-Mail Removed)> wrote in message
> >> news:(E-Mail Removed)...
> >> > Can you post your ACL in and out?
> >> >
> >> > "Aaron Anderson" <(E-Mail Removed)> wrote in message
> >> > news:(E-Mail Removed)...
> >> >> I'm not sure if this is in the right place. If anyone can recommend

a
> >> > better
> >> >> newsgroup for networking and related info, please advise.
> >> >>
> >> >>
> >> >> I have a simple question.
> >> >>
> >> >> I host my own email server. MX records direct the mail through a

third
> >> > party
> >> >> spam filtering service (mxlogic.com)
> >> >>
> >> >> It is my understanding that I should only allow incoming connections
> >> >> to
> >> >> my
> >> >> server from their posted IP addresses ( 66.179.26.128/26)
> >> >>
> >> >> If I change the ACL on my firewall, then no clients are able to send
> >> >> email...
> >> >>
> >> >> Does this make sense? I think I'm missing a piece of the puzzle....
> >> >>
> >> >>
> >> >
> >> >
> >>
> >>

> >
> >

>
>



 
Reply With Quote
 
Aaron Anderson
Guest
Posts: n/a

 
      03-20-2006, 01:37 AM
Right. It is on an internal private internal network. When I am internal all
will work perfectly with the inbound ACL set. But if I take the laptop home,
it won't be able to send mail, because my home ip address isn't in the
access list...

following?


"Neteng" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> Your mail server is in your private network correct? Are you trying to
> send
> mail when your outside your network (going through your mail server
> though)?
> When you are on your network and you send an email, the communication
> between you and your mail server never hits the firewall so it is not
> being
> blocked there. If you have an ACL on the inside/trusted interface of your
> firewall, you need to allow your mail server IP address out to anywhere on
> TCP port 25. This allows your mail server to send emails out to the world.
> Incoming should be what you had stated earlier, from 66.179.26.128 -
> 66.179.26.190 only, again on TCP port 25 (unless they use a different
> port).
>
>
>
> "Aaron Anderson" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed)...
>> ignore my last post.
>>
>> If i'm at home, and send an email, I will need access to port 25, on my
>> mailserver.
>>
>> if i restrict all incoming traffic to that of mxlogic's servers, how will
>> the mail that I send get anywhere?
>>
>> at this point, i have no outbound restrictions on the servers.
>>
>>
>>
>>
>> "Neteng" <(E-Mail Removed)> wrote in message
>> news:(E-Mail Removed)...
>> > Do you have two ACL's, one inbound and one outbound? Email going out
>> > should
>> > be going through your mail server and that is the only box that should
>> > need
>> > TCP 25 going out.
>> >
>> > "Aaron Anderson" <(E-Mail Removed)> wrote in message
>> > news:(E-Mail Removed)...
>> >> Not easily. it's a sonicwall firewall.
>> >>
>> >> Basically if I set the SMTP server to only accept incoming traffic
>> >> from
>> >> mx
>> >> logic (66.179.26.128 - 66.179.26.190) then I wouldn't be able to
>> >> send
>> > mail
>> >> from my personal computer, because my external IP wouldn't be in the
>> > rule...
>> >>
>> >>
>> >> "Neteng" <(E-Mail Removed)> wrote in message
>> >> news:(E-Mail Removed)...
>> >> > Can you post your ACL in and out?
>> >> >
>> >> > "Aaron Anderson" <(E-Mail Removed)> wrote in message
>> >> > news:(E-Mail Removed)...
>> >> >> I'm not sure if this is in the right place. If anyone can recommend

> a
>> >> > better
>> >> >> newsgroup for networking and related info, please advise.
>> >> >>
>> >> >>
>> >> >> I have a simple question.
>> >> >>
>> >> >> I host my own email server. MX records direct the mail through a

> third
>> >> > party
>> >> >> spam filtering service (mxlogic.com)
>> >> >>
>> >> >> It is my understanding that I should only allow incoming
>> >> >> connections
>> >> >> to
>> >> >> my
>> >> >> server from their posted IP addresses ( 66.179.26.128/26)
>> >> >>
>> >> >> If I change the ACL on my firewall, then no clients are able to
>> >> >> send
>> >> >> email...
>> >> >>
>> >> >> Does this make sense? I think I'm missing a piece of the puzzle....
>> >> >>
>> >> >>
>> >> >
>> >> >
>> >>
>> >>
>> >
>> >

>>
>>

>
>



 
Reply With Quote
 
Neteng
Guest
Posts: n/a

 
      03-20-2006, 01:15 PM
You will have to open your ACL up to those address spaces or everywhere.
Make sure you enable authentication for relay or you'll be blacklisted
quickly. Depending on your firewall, you might be able to do something like
lock-n-key ACL. I don't work with Sonicwall's too much, so you'll have to
research that. You could also VPN in or use webmail.


"Aaron Anderson" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> Right. It is on an internal private internal network. When I am internal

all
> will work perfectly with the inbound ACL set. But if I take the laptop

home,
> it won't be able to send mail, because my home ip address isn't in the
> access list...
>
> following?
>
>
> "Neteng" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed)...
> > Your mail server is in your private network correct? Are you trying to
> > send
> > mail when your outside your network (going through your mail server
> > though)?
> > When you are on your network and you send an email, the communication
> > between you and your mail server never hits the firewall so it is not
> > being
> > blocked there. If you have an ACL on the inside/trusted interface of

your
> > firewall, you need to allow your mail server IP address out to anywhere

on
> > TCP port 25. This allows your mail server to send emails out to the

world.
> > Incoming should be what you had stated earlier, from 66.179.26.128 -
> > 66.179.26.190 only, again on TCP port 25 (unless they use a different
> > port).
> >
> >
> >
> > "Aaron Anderson" <(E-Mail Removed)> wrote in message
> > news:(E-Mail Removed)...
> >> ignore my last post.
> >>
> >> If i'm at home, and send an email, I will need access to port 25, on my
> >> mailserver.
> >>
> >> if i restrict all incoming traffic to that of mxlogic's servers, how

will
> >> the mail that I send get anywhere?
> >>
> >> at this point, i have no outbound restrictions on the servers.
> >>
> >>
> >>
> >>
> >> "Neteng" <(E-Mail Removed)> wrote in message
> >> news:(E-Mail Removed)...
> >> > Do you have two ACL's, one inbound and one outbound? Email going out
> >> > should
> >> > be going through your mail server and that is the only box that

should
> >> > need
> >> > TCP 25 going out.
> >> >
> >> > "Aaron Anderson" <(E-Mail Removed)> wrote in message
> >> > news:(E-Mail Removed)...
> >> >> Not easily. it's a sonicwall firewall.
> >> >>
> >> >> Basically if I set the SMTP server to only accept incoming traffic
> >> >> from
> >> >> mx
> >> >> logic (66.179.26.128 - 66.179.26.190) then I wouldn't be able to
> >> >> send
> >> > mail
> >> >> from my personal computer, because my external IP wouldn't be in the
> >> > rule...
> >> >>
> >> >>
> >> >> "Neteng" <(E-Mail Removed)> wrote in message
> >> >> news:(E-Mail Removed)...
> >> >> > Can you post your ACL in and out?
> >> >> >
> >> >> > "Aaron Anderson" <(E-Mail Removed)> wrote in message
> >> >> > news:(E-Mail Removed)...
> >> >> >> I'm not sure if this is in the right place. If anyone can

recommend
> > a
> >> >> > better
> >> >> >> newsgroup for networking and related info, please advise.
> >> >> >>
> >> >> >>
> >> >> >> I have a simple question.
> >> >> >>
> >> >> >> I host my own email server. MX records direct the mail through a

> > third
> >> >> > party
> >> >> >> spam filtering service (mxlogic.com)
> >> >> >>
> >> >> >> It is my understanding that I should only allow incoming
> >> >> >> connections
> >> >> >> to
> >> >> >> my
> >> >> >> server from their posted IP addresses ( 66.179.26.128/26)
> >> >> >>
> >> >> >> If I change the ACL on my firewall, then no clients are able to
> >> >> >> send
> >> >> >> email...
> >> >> >>
> >> >> >> Does this make sense? I think I'm missing a piece of the

puzzle....
> >> >> >>
> >> >> >>
> >> >> >
> >> >> >
> >> >>
> >> >>
> >> >
> >> >
> >>
> >>

> >
> >

>
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Sky Broadband Email (smtp) Question? G a z . Broadband 1 04-23-2007 05:09 PM
SMTP Server Relay Question Bill Seymour Windows Networking 0 11-18-2005 07:55 AM
SMTP Server Relay Question Dale Allen Windows Networking 6 11-09-2005 05:18 AM
Plusnet Broadband Plus SMTP question Mark Carver Broadband 16 04-09-2005 12:01 AM
iptables firewall making smtp/pop3 slow in response Tobias Skytte Linux Networking 4 01-20-2004 12:08 AM



1 2 3 4 5 6 7 8 9 10 11