would not make a difference.
10.0.0.0
255.0.0.0
incorporates
10.30.0.0
255.255.0.0

Relay Protection is a bit un-needed if you are behind a firewall using a
private address range.  I think that you should just leave open relay since
the firewall is just forwarding inbound mail to your exchange or IMAIL
server and outbound mail will do the same.

Using NAT would not bode well with Mail servers that identify themselves
with unroutable addresses.  Proxied ARP would work, but not NAT unless you
have a delivered service filter set up.  This is all un-needed complexity
however, and I think you should just tell IMAIL to forward all outbound MAIL
through the firewall.  You can set that option in the Control Panel.
-V

----- Original Message -----
From: Fontelera, Jaime C. <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Monday, July 12, 1999 12:42 PM
Subject: RE: [IMail Forum] Testing for OPEN relay


> We use Network Address Translation in our firewall.  We use class A
private
> addresses and
> are translated to one valid IP address in the Internet. As a matter of
fact,
> only one valid IP
> address goes out from our network because we are also using Hide NAT in
our
> firewall. I don't think that our private addresses are leaked onto the
> Internet like you mentioned in your email.
>
> Maybe instead of putting 10.0.0.0 subnet 255.0.0.0 on the Relay Option, I
> should have
> added the real network address and their subnet mask. Example: 10.30.0.0
> subnet mask 255.255.0.0
>
> Any thoughts ?
>
> -----Original Message-----
> From: ## Dusty Carden [mailto:[EMAIL PROTECTED]]
> Sent: Monday, July 12, 1999 9:05 AM
> To: [EMAIL PROTECTED]
> Subject: Re: [IMail Forum] Testing for OPEN relay
>
>
> In order to secure your server from external relay the
> addresses must be valid Internet addresses for the ports
> that are exposed to the public.
>
> Private IP addresses exposed like this not only are a relay
> risk but also could create routing problems on the Internet.
>
> Dusty
>
> ----- Original Message -----
> From: Fontelera, Jaime C. <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Sent: Monday, July 12, 1999 10:48 AM
> Subject: RE: [IMail Forum] Testing for OPEN relay
>
>
> I selected the Group of Computers option in Relay.  Our internal IP
> address are all private addresses.  The start with 10.x.x.x .
> This is exactly what I entered:
>
> IP Address:  10.0.0.0
> Subnet mask: 255.0.0.0
>
> We have over 1000 desktop.  I don't think it's practical to all of them.
>
>
>
>
> Please visit http://www.ipswitch.com/support/mailing-lists.html
> to be removed from this list.
> Please visit http://www.ipswitch.com/support/mailing-lists.html
> to be removed from this list.
>

Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

Reply via email to