Educause Security Discussion mailing list archives

Re: smtp redirection


From: Mark Borrie <mark.borrie () OTAGO AC NZ>
Date: Wed, 11 May 2005 10:47:24 +1200

We set up MX records for all mail destinations to point to our
mailhubs, which then deliver directly to the destinations. We then
block smtp traffic for systems except our mailhubs.

Our mailhubs use sendmail so the delivery is achieved by using
mailertable entries of the form

servicename     smtp:[servername]

where servicename is the DNS MX name and servername is DNS
server hosting the service.

The various mail servers on campus must smart route their outgoing
mail to a mailhub to ensure off campus delivery.  We restrict the
mailhubs to only accept connections from local defined servers or
generic servers sending mail to local addresses. This helps restrict
compromised desktops from potentially spewing spam/viruses onto
the net.

Mark

On 10 May 2005 at 16:18, John wrote:

I am very pleased to hear of the success when redirecting ALL email through
the mailhub. I like the idea. My question now is how best to do this. My
preferred way is to simply disallow incoming smtp to any other host by a
router acl or a firewall rule. Is this the method you use?  Is there another
way to accomplish routing ALL incoming smtp to the mailhup/anti-spam
appliance?

John
--
Mark Borrie
IT Security Officer,
Information Technology Services, University of Otago,
Dunedin, N.Z.
Ph +64 3 479-8395, Fax +64 3 479-5080, Mobile +64 27 609-6409

**********
Participation and subscription information for this EDUCAUSE Discussion Group discussion list can be found at 
http://www.educause.edu/groups/.

Current thread: