If it is a persistent connection, yes.

 

I do this now for a client. There is a VPN between my servers and their
network. Using Sonicwall Enhanced OS, you can control exactly what traffic
is allowed across the VPN, so it is limited to only those protocols the
client subscribes to the services for. Example, for this client I provide
email gateway services. So the only traffic allowed through the VPN is SMTP.

 

John T

 

From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Jon Weisman
Sent: Friday, August 17, 2007 9:45 AM
To: [email protected]
Subject: Re: [IMail Forum] being a smart host without being an open relay

 

What if their exchange servers VPN'd into your mail servers? You could use
the private ip.

 

-Jon

 

----- Original Message ----- 

From: Darin Cox <mailto:[EMAIL PROTECTED]>  

To: [email protected] 

Sent: Friday, August 17, 2007 12:24 PM

Subject: Re: [IMail Forum] being a smart host without being an open relay

 

You have two main options

 

1. Have them get a static IP, or

 

2. Have their Exchange server POP the messages from your server.
Unfortunately, Exchange POP connectors cannot be configured to POP more
frequently than every 15 minutes.

 

That said, if they are using a dynamic DNS (DDNS) service, you could
configure your server to relay to a hostname that is continually updated
with the current IP via DDNS.  Their may be some delays when the IP changes,
depending on how quickly the DDNS is updated, and the TTL on the records.

 

By far, the best solution is for them to spend a little more, and get a
static IP.


Darin.

 

 

----- Original Message ----- 

From: Adam Greene <mailto:[EMAIL PROTECTED]>  

To: [email protected] 

Sent: Friday, August 17, 2007 11:47 AM

Subject: [IMail Forum] being a smart host without being an open relay

 

Hi!

 

We're being approached by a networking company whose customers need Smart
Host services. i.e. they run Exchange servers and are being blacklisted
because some of the Exchange servers are assigned dynamic IP addresses. They
want the Exchange servers to relay through us, so as not to get blacklisted.


 

I don't quite understand how they could even be receiving email reliably
with a dynamic IP address on their mail server; I'm checking with the
networking company now. Maybe they're using some kind of dynamic DNS
service?

 

Anyways, I'm thinking about how to provide this service without becoming an
open relay. I need the Exchange server to authenticate to Imail somehow.
There's also the issue of outbound port 25 being blocked by many major
ISP's.

 

We've toyed with the idea of requiring SSL connections on port 465 from the
Exchange server, but I'm not sure of what kind of server-to-server
authentication I can set up in Imail to prevent us from becoming an open
relay. 

 

Is someone else already doing this with Imail? What solution have you come
up with?

 

Thanks,

Adam

 

 

Reply via email to