
Code Blue
•
259 Hedcor Street
•
Holland, MI 49423 USA
•
800.205.7186
•
www.codeblue.com GU-154-F
page 123 of 132
ToolVox® X3
Administrator Guide
HELO is required
EnablingthisoptioncausesPostxtorequireclientstointroducethemselveswithaHELOheader
atthebeginningofanSMTPsession.ThismaypreventsomeUCEsoftwarepackagesfrom
connecting,althoughitmayalsoimpactotherlegitimateclients.Thisoptioncorrelatestothesmtpd_
helo_requiredanddefaultstoNo.
Allow untrusted routing
ThisoptioncongureswhetherPostxwillforwardmessageswithsender-specied routingfrom
untrustedclientstodestinationswithintheacceptedrelaydomains.Thisfeatureclosesapotential
loopholeinaccesscontrolsthatwouldnormallypreventtheserverfrombeinganopenrelayfor
spammers.Ifthisbehaviorisallowed,amalicioususercouldexploitabackupMXmailhostinto
forwardingjunkmailtoaprimaryMXserverthatbelievesthemailhasoriginatedfromalocal
address.Thisoptioncorrelatestotheallow_untrusted_routingandisdisabledbydefault.Enabling
thisoptionshouldbedonewithextremecautiontopreventturningyourPostxinstallationintoan
open relay.
Restrict ETRN command upon...
TheSMTPETRNcommandisaclumsymeansforclientsthatarenotalwaysconnectedtothe
Internettoretrievemailfromtheserver.Theusageofthiscommandisratheroutdatedandrarely
used,asPOP3andIMAParebettersuitedtosolvethisproblem.Thisoptioncorrelatestothe
smtpd_etrn_restrictionsdirectiveandthedefaultistoallowETRNfromanyhost.Thisoption
acceptsthefollowingdirectives:check_etrn_accessmaptype:mapname,permit_naked_ip_address
,reject_invalid_hostname,check_helo_accessmaptype:mapname,reject_maps_rbl,reject_
unknown_client,permit_mynetworks,check_client_access,permit,reject,warn_if_reject,and
reject_unauth_pipelining.
Thisoption,aswellasthefollowingthreeRestrictions...options,acceptoneorallofthefollowing
valuesinthetexteld.Eachisdescribedonlyoncehereandthespecicentrywillincludethelistof
accepteddirectivesfortheoption.Theimpactofsomeofthesechoicesdependsonconguration
performedelsewhere,andcouldpotentiallyopensecurityholesifnotconguredcarefully.
permit_mynetworks
Permitthemessageiftherelevantaddress(senderorrecipient,dependingontherestriction)is
withinthelocalnetwork.
reject_unknown_client
TherequestwillberefusediftheclientIPhasnoPTRrecordintheDNS.Thismeansaclientwith
anIPaddressthatcannotberesolvedtoahostnamecannotsendmailtothishost.
check_client_accessmaptype:mapname
Thisoptionrequirestheinclusionofanalreadyconguredmap.Thiswillrestrict,basedonthe
contentsofthemap,allowingonlyclientsthatareallowedbythemap.Themapmaycontain
networks,parentdomainsorclientaddresses,andPostxwillstripoffunnecessaryinformationto
matchtheclienttothelevelofspecicityneeded.
check_sender_accessmaptype:mapname
Comentarios a estos manuales