LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Closed Thread
  Search this Thread
Old 03-31-2010, 12:27 PM   #1
andy.l
Member
 
Registered: Feb 2007
Location: Scandinavia
Distribution: Centos/Redhat
Posts: 97

Rep: Reputation: 15
Question Secure setup - smtp on firewall?


Hi

I'm about to deploy a new firewall based on Astaro Linux. This firewall have the option to function as a smtp mail relay for my internal mailserver for all incoming mail. At first this seems like a nice setup, but wouldn´t this be a potential security risk? This would make my firewall vulnerable for DOS attacks on port 25. The normal setup would be to put a smtp relay in the DMZ and have that relay all incoming mail to my internal mailserver.
Are there any one who has experience with using a firewall/UTM as both firewall and SMTP relay for incoming and outgoing mail.

/A
 
Old 04-01-2010, 06:06 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by andy.l View Post
wouldn´t this be a potential security risk? This would make my firewall vulnerable for DOS attacks on port 25.
It's not specific to running a relay or the MTA connected directly or in a DMZ. Basically a DoS can happen to any exposed device be it a router, MTA or firewall. If you read the SMTP relay section help of Astaro Linux Firewall you'll get an overview of the risks the relay protects against. AFAIK DoS is not among those because that's a play between you and your service provider. One way to have redundancy slash somewhat mitigate an email DoS situation could be to run the main MTA yourself and run each of your backup MXes (you do have backup MX records, right?) at a different provider.
 
1 members found this post helpful.
Old 04-05-2010, 07:39 PM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Let us know if http://www.linuxquestions.org/questi...actice-800175/ supersedes this question. No need to keep n threads alive on aprox the same topic.
 
Old 04-06-2010, 12:17 AM   #4
andy.l
Member
 
Registered: Feb 2007
Location: Scandinavia
Distribution: Centos/Redhat
Posts: 97

Original Poster
Rep: Reputation: 15
The new one superseeds this, så we can close this one.
 
Old 04-06-2010, 12:44 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by andy.l View Post
The new one superseeds this
Next time please report it using the Report button on your original post.
 
  


Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Sendmail with Secure SMTP-AUTH allinurl Linux - Networking 1 04-01-2009 02:57 AM
How to set up secure smtp server keevitaja Linux - Server 4 03-13-2008 11:19 PM
too many smtp in /var/log/secure amedjones Linux - Security 3 03-09-2008 02:13 PM
firewall setup and MX smtp router gizbourn Linux - Networking 0 02-18-2004 07:03 AM
help with client side NFS-firewall setup and server side NIS-firewall setup niverson Linux - Networking 3 02-02-2004 08:52 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:32 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration