Pessoal,
Boa tarde.
Vamos aos fatos, estou tirando um servidor de email  e colocando um outro
rodando postfix:
antigo -> 10.0.0.40 | Red Hat | Postfix + amavis + spamassassim 
novo -> 10.0.0.100  | Freebsd | Postfix + amavis + spamassassim +
AUTENTICACAO AD
No firewall, apenas troquei onde era o ip 10.0.0.40 por 10.0.0.100
Fatos:
- autenticacao no AD OK, tanto pelo roundcube como Outlook
- em /var/log/maillog vejo as mensagens chegando OK
- NO ENVIO, tanto para uma conta de meu dominio como para outra conta
externa, recebo erro de bulk: 

Considered UNSOLICITED BULK EMAIL, apparently from you
Reporting-MTA: dns; marcelo.com.br
Received-From-MTA: smtp; marcelo.com.br ([127.0.0.1])
Arrival-Date: Sat, 12 Jun 2010 15:40:26 -0300 (BRT)

Final-Recipient: rfc822;[email protected]
Action: failed
Status: 5.7.0
Diagnostic-Code: smtp; 554 5.7.0 Reject, id=01077-03 - SPAM
Last-Attempt-Date: Sat, 12 Jun 2010 15:40:26 -0300 (BRT)
Final-Log-ID: 01077-03/2crZUbtK0Tte

Nota: dominio ficticio

- SAIDA postconf -n:
smtp# postconf -n
alias_maps = hash:/etc/aliases
broken_sasl_auth_clients = yes
command_directory = /usr/local/sbin
config_directory = /usr/local/etc/postfix
content_filter = smtp-amavis:[localhost]:10024
daemon_directory = /usr/local/libexec/postfix
debug_peer_level = 2
home_mailbox = Maildir/
html_directory = no
mail_owner = postfix
mailq_path = /usr/local/bin/mailq
manpage_directory = /usr/local/man
mydestination = localhost.$mydomain, localhost
mydomain = marcelo.com.br
myhostname = marcelo.com.br
mynetworks = 10.0.0.0/8,127.0.0.0/8,200.1xx.xx.x
myorigin = $mydomain
newaliases_path = /usr/local/bin/newaliases
queue_directory = /var/spool/postfix
readme_directory = no
sample_directory = /usr/local/etc/postfix
sendmail_path = /usr/local/sbin/sendmail
setgid_group = maildrop
smtp_tls_note_starttls_offer = yes
smtp_use_tls = yes
smtpd_banner = $myhostname ESMTP $mail_name ($mail_version)
smtpd_recipient_restrictions = permit_sasl_authenticated,
permit_mynetworks, reject_unauth_destination
smtpd_sasl_auth_enable = yes
smtpd_sasl_authenticated_header = yes
smtpd_sasl_local_domain = $myhostname
smtpd_sasl_path = /var/run/dovecot/auth-client
smtpd_sasl_security_options = noanonymous
smtpd_sasl_type = dovecot
smtpd_sender_restrictions = permit_sasl_authenticated, permit_mynetworks
smtpd_tls_CAfile = /etc/ssl/postfix/smtpd.pem
smtpd_tls_cert_file = /etc/ssl/postfix/smtpd.pem
smtpd_tls_key_file = /etc/ssl/postfix/smtpd.pem
smtpd_tls_loglevel = 0
smtpd_tls_received_header = yes
smtpd_tls_session_cache_timeout = 3600s
smtpd_use_tls = yes
tls_random_source = dev:/dev/urandom
unknown_local_recipient_reject_code = 550
virtual_alias_maps = hash:/usr/local/etc/postfix/virtual
virtual_gid_maps = static:1000
virtual_mailbox_base = /var/virtual
virtual_mailbox_domains = marcelo.com.br
virtual_mailbox_maps = hash:/etc/aliases,
ldap:/usr/local/etc/postfix/ldap-users.cf
virtual_transport = dovecot
virtual_uid_maps = static:1000


- arquivo rc.conf:
# -- sysinstall generated deltas -- # Fri Jan 22 07:01:00 2010
# Created: Fri Jan 22 07:01:00 2010
# Enable network daemons for user convenience.
# Please make all changes to this file, not to /etc/defaults/rc.conf.
# This file now contains just the overrides from /etc/defaults/rc.conf.
defaultrouter="10.0.0.1"
hostname="smtp"
ifconfig_xl0="inet 10.0.0.100  netmask 255.255.255.0"

- arquivo hosts:
::1                     localhost
127.0.0.1               localhost localhost.marcelo.com.br smtp
marcelo.com.br 
10.0.0.100             marcelo.com.br smtp
10.0.0.100             marcelo.com.br.

- firewall
Mesmo testando sem o firewall o problema persiste, mas para desencargo
segue a regra do firewall(que funciona no postfix antigo)
# regras do servidor de email
#novo email
-A PREROUTING -d ip_externo -p TCP --dport 25 -j DNAT --to 10.0.0.100
-A POSTROUTING -s 10.0.0.0/24 -p TCP --dport 25 -j SNAT --to ip_externo
-A PREROUTING -s 10.0.0.0/24 -p TCP --dport 110 -j DNAT --to 10.0.0.100
-A POSTROUTING -s 10.0.0.0/24 -p TCP --dport 110 -j SNAT --to ip_externo
-A PREROUTING -i eth1 -p TCP --dport 110 -j DNAT  --to 10.0.0.100:110
-A PREROUTING -i eth1 -p TCP --dport 25 -j DNAT  --to 10.0.0.100:25

Alguém com alguma LUZ ? Agradeço
_______________________________________________
Postfix-BR mailing list
[email protected]
http://listas.softwarelivre.org/mailman/listinfo/postfix-br

Responder a