Jaime,
I think you are missing the point. Look at the top few lines of the
transcript I sent to you. It is your firewall itself that is acting as an
open relay. Firewalls often do this. People think if I put up a firewall I
am safe, but the truth is (as you have seen) that without proper
configuration they can actually make things worse. I don't think that your
IMAIL server settings can do anything about what your firewall is doing do
you? You need to understand (quick smile so that you know I am not getting
frustrated with you) that you can beat your head in to the ground changing
IMAIL settings and it will still be your firewall getting you in trouble.
It is acting as a relay sending messages to and from your IMAIL server. The
problem comes in that it is also relaying mail for the rest of the world.
You have gained some new expertise in the area of relay by your efforts, but
other than that you have been wasting your time. You have got to lock down
your FIREWALLS mail component ASAP. IMAIL is behind your firewall - so it
is your firewall that is responsible for activity on the internet. If your
firewall were configured to only relay mail that was either
1. bound for your IMAIL machine, or
2. from your IMAIL machine
you would be in better shape and would in fact have already fixed the
problem.
You must work with Checkpoint to determine the settings required to properly
secure the "mail-proxy" feature of your firewall. The goal is the same...
set the FIREWALL to only relay mail bound for or from one of your IP
addresses.
Best Regards!
-V
----- Original Message -----
From: Fontelera, Jaime C. <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Friday, July 16, 1999 6:04 PM
Subject: RE: [IMail Forum] Open E-mail Relay
> Can someone help me in configuring the I-mail server to STOP acting
> as an open mail relay. I can't believed it's still saying open relay when
> I already added: all my private networks IP addresses in the " Relay Mail
> > For". Does the SMTP Relay Mail For option ONLY works for valid network
IP
> addresses ?
>
> Thanks,
> Jaime
>
>
> -----Original Message-----
> From: Vaughn Thurman [mailto:[EMAIL PROTECTED]]
> Sent: Thursday, July 15, 1999 8:40 PM
> To: [EMAIL PROTECTED]
> Subject: Re: [IMail Forum] Open E-mail Relay
>
>
> Bad news... here is the transcript.
> -V
>
> Connecting to 209.233.174.11 ...
> <<< 220 CheckPoint FireWall-1 secure SMTP server
> >>> HELO maps1.pa.vix.com
> <<< 250 Hello maps1.pa.vix.com, pleased to meet you
> >>> MAIL FROM:<nobody@[209.233.174.11]>
> <<< 250 <nobody@[209.233.174... Sender ok
> >>> RCPT TO:<[EMAIL PROTECTED]>
> <<< 250 <[EMAIL PROTECTED] Recipient ok
> >>> DATA
> <<< 354 Enter mail, end with "." on a line by itself
> >>> (message body)
> <<< 250 Ok
> >>> QUIT
> <<< 221 Closing connection
> rlytest: relay accepted - final response code 221
>
> ------------------------------------------------------------
>
> Test complete.
>
> PROBLEM! Host [209.233.174.11] may be vulnerable to mail relay.
>
>
> <end transcript>
>
> ----- Original Message -----
> From: Fontelera, Jaime C. <[EMAIL PROTECTED]>
> To: I-mail <[EMAIL PROTECTED]>
> Sent: Thursday, July 15, 1999 6:31 PM
> Subject: [IMail Forum] Open E-mail Relay
>
>
> > Hi I-mail admins !
> >
> > I configured my I-mail ( 4.x) version to use SMTP security " Relay Mail
> > For". On address, I selected my private network
> > address 10.x.x.x. as my host. I also configured my firewall to accept
only
> > *@solanocounty.com. Can someone check for open mail relay connection.
My
> > valid IP address is: 209.233.174.11.
> >
> > Thanks,
> >
> >
> >
> >
> >
> > Jaime C. Fontelera
> > Internet Services Systems Administrator
> > mailto:[EMAIL PROTECTED]
> > 707-421-6340
> >
> > Please visit http://www.ipswitch.com/support/mailing-lists.html
> > to be removed from this list.
> >
>
> Please visit http://www.ipswitch.com/support/mailing-lists.html
> to be removed from this list.
> Please visit http://www.ipswitch.com/support/mailing-lists.html
> to be removed from this list.
>
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.