11 messages in net.sourceforge.lists.courier-usersRE: [courier-users] Courier behind a ...
FromSent OnAttachments
Dan JohanssonOct 3, 2002 8:11 am 
Bowie BaileyOct 3, 2002 8:40 am 
Alexander LazicOct 3, 2002 8:42 am 
Jesse KeatingOct 3, 2002 8:46 am 
Smith, Mark Andrew STOct 3, 2002 9:16 am 
Zenon PanoussisOct 3, 2002 9:25 am 
Peter C. NortonOct 3, 2002 9:58 am 
Dan JohanssonOct 6, 2002 3:09 am 
Alexander LazicOct 6, 2002 3:25 am 
Alexei Batyr'Oct 6, 2002 3:52 am 
Alexander LazicOct 6, 2002 4:07 am 
Actions with this message:
Paste this link in email or IM:
Paste this link in email or IM:
Atom feed for this thread
Paste this URL into your reader:
Subject:RE: [courier-users] Courier behind a FirewallActions...
From:Bowie Bailey (Bowi@BUC.com)
Date:Oct 3, 2002 8:40:42 am
List:net.sourceforge.lists.courier-users

-----Original Message----- From: Dan Johansson [mailto:Dan.@bluewin.ch] Sent: Thursday, October 03, 2002 11:12 AM To: cour@lists.sourceforge.net Subject: [courier-users] Courier behind a Firewall

Hi,

I´m new to Courier and this list so please be kind to me.

I´ve set up Courier succefull (I think) on a host in my network. This Network is behind a Firewall (consisting of a Router (doing NAT) and a hardened Linux box). Courier works fine for "internal" mail, and now I would like it to recieve mail from te rest of the world. So my qustion is what to do on the FW. Schould I only put some general- gateway on my FW that only passes TCP-connections on port 25 from the WAN sid to the Courier Mail-Server on the LAN side.

The Courier box will need to have a static IP to the outside (probably via a static NAT on your router). Then just tell the firewall to allow connections to port 25 on your Courier box. I could give you instructions for a Cisco firewall, but I'm not familiar enough with iptables (or ipchains).

Or do you have any othe suggestion (No I don´t want to run my mailserver on the FW).

Running extra software on your firewall is generally not a good idea if you can avoid it. If you do, then a vulnerability in your other applications could give a hacker direct access to your firewall box.

Regards, --Dan

Bowie