On Fri, May 24, 2002 at 04:58:39PM -0500, Jerry Amundson wrote: > >Public services should be placed in the dmz, and not even > >the dmz should be allowed to create connections into the > >internal net. > > Except for the mail hub smtp'ing to/from the internal mail server, right?
You could probably avoid this by using serialmail and ssh. I don't know if its worth the cost, but ssh'ing from the internal server to the dmz server, then forwarding a port from localhost on the dmz server to the remote server, and just having serialmail run over that forwarded connection would substantially reduce the hole. Fetchamail could serve the same purpose, but with the substantial issue of relying on fetchmail. I suspect that for most people, having users check email on the dmz smtp server, or an imap/pop3 server in the dmz would be a lot more practical. -- The 5 year plan: In five years we'll make up another plan. Or just re-use this one. _______________________________________________________________ Don't miss the 2002 Sprint PCS Application Developer's Conference August 25-28 in Las Vegas -- http://devcon.sprintpcs.com/adp/index.cfm _______________________________________________ courier-users mailing list [EMAIL PROTECTED] Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users
