LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-11-2008, 07:58 AM   #1
melainine
LQ Newbie
 
Registered: Feb 2008
Posts: 15

Rep: Reputation: 0
how to configure firewall for port 25


how to configure my firewall so that only my actual mail server can send data out on port 25 where i have a lan and using nat method ...
help will be appreciated

thank you
 
Old 02-11-2008, 08:03 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
we can't help you if you don't tell us anything about this firewall...
 
Old 02-11-2008, 08:28 AM   #3
melainine
LQ Newbie
 
Registered: Feb 2008
Posts: 15

Original Poster
Rep: Reputation: 0
will , am using fedora and sendmail , last days i found that am blocked and in senderscore.org i found that other domain such "1cho.com" and "el-puente.de" and "jemp.com.br" sends mail using my IP ,
now the goal is to stop them, i dont know how they could use my ip ???


and this prob is killing me , cause all the employees cant send mails for yahoo and hotmail and others ...


help will be appreciated
 
Old 02-11-2008, 08:33 AM   #4
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
Generally your isp would provide an smtp relay host to validate you. Have they defined one for your use?
 
Old 02-11-2008, 08:42 AM   #5
melainine
LQ Newbie
 
Registered: Feb 2008
Posts: 15

Original Poster
Rep: Reputation: 0
i have my own dns and i have rdns and i configured mailserver for our little company
 
Old 02-11-2008, 08:45 AM   #6
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
OK, well your ISP still may have this within their internet architecture... It is more something used by home users on dynamic IP addresses, but is still valid for businesses often. If your IP has been incorrectly blacklisted you can check it out at a site like this... http://www.spamhaus.org/lookup.lasso
 
Old 02-11-2008, 08:56 AM   #7
melainine
LQ Newbie
 
Registered: Feb 2008
Posts: 15

Original Poster
Rep: Reputation: 0
thank you so much ...

this information from senderscore.org

Sending Domains (3)
We've seen your IP sending email for these domains.
Domain Authenticated
1cho.com No
el-puente.de No
jemp.com.br No


and my external reputaion POOR

how did these domains could used my IP for send spam ???
 
Old 02-11-2008, 09:01 AM   #8
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
Are you running an incoming mailserver as well? If so, have you checked if it is an open relay? If it's configured as an open relay, anyone could use your mailserver to send spam.
 
Old 02-11-2008, 09:01 AM   #9
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
well those sites themselves don't look like spam senders... look like very genuine businesses, so they've been as done over as you by another real spammer. have you checked yourself for being an open relay? http://www.abuse.net/relay.html
 
Old 02-11-2008, 09:09 AM   #10
melainine
LQ Newbie
 
Registered: Feb 2008
Posts: 15

Original Poster
Rep: Reputation: 0
yes, i did check am not an open-relay and i have rDNS and SPF but these site or spammers using their names and my IP to send spam to ppl
 
Old 02-11-2008, 09:14 AM   #11
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
Have you performed a capture of your network traffic to see if there are any signs of the SPAM to help you determine the source?
 
Old 02-11-2008, 09:17 AM   #12
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
Are we getting sidetracked here...? Do you still just want the answer to your initial question? it doesn't seem to bare any resemblance to where we've now ended up...
 
Old 02-11-2008, 09:22 AM   #13
melainine
LQ Newbie
 
Registered: Feb 2008
Posts: 15

Original Poster
Rep: Reputation: 0
acid_kewpie : yes i still want the answer but i just added that to give you clear pic of what i want ...

yes i did not see any mail going in the log as a spam but i can see spam come to my users
 
Old 02-11-2008, 09:25 AM   #14
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
well spam will come in if it's spam for your users... so looking at the firewall, you've still not said what it is... is this sendmail box behind it? or is it it? if you wish to recieve mail then you're going to still need to allow inbound connections anyway, which won't affect your spam situation.
 
Old 02-11-2008, 09:25 AM   #15
melainine
LQ Newbie
 
Registered: Feb 2008
Posts: 15

Original Poster
Rep: Reputation: 0
i want to know how they can get my ip and how to block them from using it ,
cause these days am always blocked and de-blocked
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
port 25 filtered despite firewall having port 25 open ille.pugil42 Linux - Security 8 03-09-2007 12:51 AM
How to configure my firewall 144419855310001 Linux - Security 7 08-19-2006 09:39 AM
how to configure my firewall cd1680 Linux - Security 11 03-17-2005 08:41 PM
Need to configure firewall aargh Fedora 3 09-17-2004 02:34 PM
firewall.rc.config says :"open port 8080" but nmap says port is closed saavik Linux - Security 2 02-14-2002 12:16 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:23 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration