Firewall Wizards mailing list archives

Re: Allowing relay through Watchguard Firebox 1000


From: Paul Robertson <proberts () patriot net>
Date: Sat, 21 Feb 2004 14:41:32 -0500 (EST)

On Sat, 21 Feb 2004, Bob Alberti wrote:

They have recently started deploying e-mail enabled cell phones. Cell phone
users can reply to messages from other employees, but cannot relay mail from
their cell phones outside the domain (i.e. to customers), responding with
the rather odd error

"553 Requested action not taken: mailbox name not allowed or chunk too
large"

Maybe this is just me misunderstanding...


That's actually fine -- normally they don't WANT relaying of course -- but I
have been unsuccessful in my attempts to tell the firebox "It's okay to
relay from this domain or this set of IP addresses."  Part of the difficulty
is that this is a production system, so my ability to experiment is
limited -- my last test, carefully executed after hours, resulted in all
inbound mail being cut off for a time.

They're sending mail from their cell phones, with a return-path of thier
work address, with a forward path of their customers?

I don't see how their firewall fits in - unless this is one of those
"Phone is one of those multifunction PDA things sitting in a cradle?"

If so, I'd relay those off a different internal server and let it make the
relay choice based on the IP address.

Paul
-----------------------------------------------------------------------------
Paul D. Robertson      "My statements in this message are personal opinions
proberts () patriot net      which may have no basis whatsoever in fact."
probertson () trusecure com Director of Risk Assessment TruSecure Corporation
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: