On Fri, May 24, 2002 at 04:58:39PM -0500, Jerry Amundson wrote:
> >Public services should be placed in the dmz, and not even
> >the dmz should be allowed to create connections into the
> >internal net.
> 
> Except for the mail hub smtp'ing to/from the internal mail server, right?

You could probably avoid this by using serialmail and ssh.  I don't
know if its worth the cost, but ssh'ing from the internal server to
the dmz server, then forwarding a port from localhost on the dmz
server to the remote server, and just having serialmail run over that
forwarded connection would substantially reduce the hole.

Fetchamail could serve the same purpose, but with the substantial
issue of relying on fetchmail.

I suspect that for most people, having users check email on the dmz
smtp server, or an imap/pop3 server in the dmz would be a lot more
practical.

-- 
The 5 year plan:
In five years we'll make up another plan.
Or just re-use this one.

_______________________________________________________________

Don't miss the 2002 Sprint PCS Application Developer's Conference
August 25-28 in Las Vegas -- http://devcon.sprintpcs.com/adp/index.cfm

_______________________________________________
courier-users mailing list
[EMAIL PROTECTED]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users

Reply via email to