LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 03-26-2009, 10:48 AM   #1
serge
Member
 
Registered: Apr 2007
Posts: 45

Rep: Reputation: 15
Transparent mail filter distribution


I have been searching far and wide and could not find a suitable solution.

Does anyone know of a distribution that provides this?

I tried these.
Endian
pfSense
Untangle

None of them seem to do the job.

My current network looks like this
WAN --> router --> LAN containing mail server

The situation I want is as follows
Between the router and the LAN containing the mail server, some sort of transparent firewall distribution that monitors all SMTP traffic and performs mail filtering by adding (for example) "(spam)" to the subject and afterwards have it being sent to the mail server as normal.
Also it should be possible to configure it by adding and removing rules for different levels of spam severity

To me this seems very possible, unfortunately I could not find such a solution.

Thanks a very big lot in advance for all the help!!
 
Old 03-26-2009, 06:09 PM   #2
archangel_617b
Member
 
Registered: Sep 2003
Location: GMT -08:00
Distribution: Ubuntu, RHEL/CentOS, Fedora
Posts: 234

Rep: Reputation: 42
Quote:
Originally Posted by serge View Post
I have been searching far and wide and could not find a suitable solution.

Does anyone know of a distribution that provides this?

I tried these.
Endian
pfSense
Untangle

None of them seem to do the job.

My current network looks like this
WAN --> router --> LAN containing mail server

The situation I want is as follows
Between the router and the LAN containing the mail server, some sort of transparent firewall distribution that monitors all SMTP traffic and performs mail filtering by adding (for example) "(spam)" to the subject and afterwards have it being sent to the mail server as normal.
Also it should be possible to configure it by adding and removing rules for different levels of spam severity

To me this seems very possible, unfortunately I could not find such a solution.

Thanks a very big lot in advance for all the help!!
It depends on what you want really. If you just want a mail filtering gateway, just push it all through a setup like Postfix+Spamassassin+ClamAV:

http://www.section6.net/wiki/index.p...Amavisd_Clamav

After filtering, the Postfix server can route any remaining good email to your LAN server. This is pretty much how mail filtering appliances work (and this is exactly how Barracudas work, afaik).

- Arch
 
Old 03-26-2009, 06:22 PM   #3
hjogoo
LQ Newbie
 
Registered: Jan 2009
Posts: 14

Rep: Reputation: 0
I would go for vexim+spamassassin+clamav. Why vexim, much easier to set the spam level.

Quote:
Originally Posted by serge View Post
I have been searching far and wide and could not find a suitable solution.

Does anyone know of a distribution that provides this?

I tried these.
Endian
pfSense
Untangle

None of them seem to do the job.

My current network looks like this
WAN --> router --> LAN containing mail server

The situation I want is as follows
Between the router and the LAN containing the mail server, some sort of transparent firewall distribution that monitors all SMTP traffic and performs mail filtering by adding (for example) "(spam)" to the subject and afterwards have it being sent to the mail server as normal.
Also it should be possible to configure it by adding and removing rules for different levels of spam severity

To me this seems very possible, unfortunately I could not find such a solution.

Thanks a very big lot in advance for all the help!!
 
Old 03-27-2009, 03:06 AM   #4
serge
Member
 
Registered: Apr 2007
Posts: 45

Original Poster
Rep: Reputation: 15
Thanks a lot for the replies!

Quote:
Originally Posted by archangel_617b View Post
It depends on what you want really. If you just want a mail filtering gateway, just push it all through a setup like Postfix+Spamassassin+ClamAV:

After filtering, the Postfix server can route (I do not want a router) any remaining good email to your LAN server. This is pretty much how mail filtering appliances work (and this is exactly how Barracudas work, afaik).
How would I go about that then?

Do I configure a bridged interface assign it an IP in the subnet both interfaces are in?
Should I make sure that filtering takes place only from the 'external' interface through iptables+physdev matching? (it is essential that the solution sits between the router and the lan without any need to change anything else on either WAN or LAN)
Does spamassasin/postfix redirect the traffic to the actual mail server when processed?
 
Old 03-30-2009, 05:29 AM   #5
serge
Member
 
Registered: Apr 2007
Posts: 45

Original Poster
Rep: Reputation: 15
Quote:
Originally Posted by serge View Post
T
How would I go about that then?

Do I configure a bridged interface assign it an IP in the subnet both interfaces are in?
Should I make sure that filtering takes place only from the 'external' interface through iptables+physdev matching? (it is essential that the solution sits between the router and the lan without any need to change anything else on either WAN or LAN)
Does spamassasin/postfix redirect the traffic to the actual mail server when processed?
I think I am starting to get it figured out

I will do the following:
  • Create a bridged interface.
  • Let iptables redirect all incoming traffic to port 25 from the external physical interface to the local postfix install.
  • Let spamassassin process the mail and if it determines it is spam prefix the subject with (SPAM) and perhaps the level of spam (not sure yet)
  • Set up the current mail server as the relay host.

What remains is, how do I make it easy to configure mails as (not) spam when they are falsely identified?

Thanks a lot so far everyone!!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Creating Mail Filter in Thunderbird mail client msivasakthi Linux - Software 1 07-14-2008 02:05 AM
Other mail server to filter spam eescaler Linux - Networking 1 01-10-2006 10:34 AM
Spam filter to external mail filter deadlock Linux - Software 1 06-16-2004 02:28 AM
filter mail stand Linux - General 1 01-17-2003 11:59 AM
Mail Filter Inflex Problem mallikarjun Linux - Networking 0 09-17-2002 06:35 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 10:12 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration