On 22/12/23 16.44, Hengga KMN wrote:
Akhirnya saya mundur lagi ke firewall router. Saya cek ada policy
tambahan di router tersebut yang tidak pernah saya request. Ternyata
dari vendor managed kita ada tambahkan blok terhadap group IP USA dan IP
Lithuania.
Karena kecurigaan saya di sana, saya minta rules itu di-take-out.
Dan benar, akhirnya di user mulai bisa terima email dari domain2 lain.
Itu firewall mengaktifkan Geolocation, tetapi salah penerapan.
Geolocation di firewall itu untuk melindungi jaringan LAN, tidak cocok
untuk melindungi internet mail server karena bahasa/protocolnya berbeda
walau sama-sama berbasis tcp/ip protocol.
Geolocation for email berbeda penerapannya. pakai bahasa Email (SMTP
Protocol) sehingga bisa dimengerti oleh sender (Internet mail server) lain.
MDaemon sudah punya mail firewall yang bisa menerapkan geolocation
disebut dengan Location Screening.
https://en.wikipedia.org/wiki/Internet_geolocation
https://en.wikipedia.org/wiki/Internet_censorship
http://mdaemon.dutaint.co.id/mdaemon/23.5/screening_location-screening.html
Location Screening
Location Screening is a geographically based blocking system that you
can use to block incoming SMTP, POP, IMAP, Webmail, ActiveSync,
AutoDiscovery, XML API, Remote Administration, CalDAV/CardDAV, XMPP, and
Minger connections from unauthorized regions of the world. MDaemon
determines the country associated with the connecting IP address and
then blocks that connection if it is from a restricted location, and
adds a line to the Screening log. For SMTP, Location Screening can
optionally block only connections using AUTH. This is useful, for
example, if you have no users in a specific country but still wish to be
able to receive mail from there. That way you would only block those
attempting to log in to your server.
--
syafril
--------
Syafril Hermansyah
MDaemon-L Moderator, run MDaemon 23.5.1
Mohon tidak kirim private mail (atau cc:) untuk masalah MDaemon.
We are products of our past, but we don't have to be prisoners of it.
--- Rick Warren
--
--[mdaemon-l]----------------------------------------------------------
Milis ini untuk Diskusi antar pengguna MDaemon Mail Server di Indonesia
Netiket: https://wiki.openstack.org/wiki/MailingListEtiquette
Arsip: http://mdaemon-l.dutaint.com
Dokumentasi : http://mdaemon.dutaint.com
Berlangganan: Kirim mail ke [email protected]
Henti Langgan: Kirim mail ke [email protected]
Versi terakhir: MDaemon 23.5.1, SecurityGateway 9.5.2