Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > Mail Security: SMTP, POP3, Antispam and Antivirus

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #11 (permalink)  
Old 05-14-2009, 01:56 PM
Alvin's Avatar
Senior Member
 
Join Date: Jul 2003
Posts: 142
Default

Ian, Bob and Billybob.

- Yes I did read about the suggestion on the DNAT but yet to implement as I was thinking there might be a easier way to do it such as maybe I configure something wrongly etc.

I proceeded to do the DNAT but somehow SMTP 25 remains open on ShieldUp.

465 and 587 is now closed with the same DNAT.

- I created a Host Blackhole with a non exist IP.

- I Created

For Port 25

1) From ANY Service SMTP Destination WAN Address
To Blackhole Service SMTP
Auto Packet Filter Rule UNchecked.

For Port 465

2) From ANY Service SMTP SSL Destination WAN Address
To Blackhole Service SMTP SSL
Auto Packet Filter Rule UNchecked.

For Port 587
I created a TCP PORT 587 in the services as I do not see it.

1) From ANY Service TCP Port 587 Destination WAN Address
To Blackhole Service TCP Port 587
Auto Packet Filter Rule UNchecked.


The result from ShieldUp is Port 25 remains OPEN.

Port 587 and Port 465 is now closed.

But I do not understand why 25 remains open.

Under SMTP Proxy, below is the settings, those not stated is not touched.

Global = Simple Mode
Domains and Routing Target = Empty.
Route by MX Records. ( It used to be Static Host List but after I tried to play around, I can no longer set it back to Static Host List which is empty thus I choose MX Records)
Host Based Relay = LAN Only.
Host / Network Blacklist = ANY
Scan Relayed (outgoing) messages = Checked
Use Transparent Mode = Checked
Use Smarthost = Checked with my ISP SMTP.
__________________
Astaro Latest Version, HP ML110 G3 Server, P4HT 3.0GHz , 3GB RAM, 3 x Broadcom Gigabit NIC
Reply With Quote
  #12 (permalink)  
Old 05-16-2009, 10:16 AM
Alvin's Avatar
Senior Member
 
Join Date: Jul 2003
Posts: 142
Default

Port 25 remains Open with DNAT.

Added Block Rule on Top in Packet Filter still remains open.

Just to confirm my DNAT is right, I disable DNAT and other ports open, so I am doing correctly just that somehow the other 2 ports will close but somehow 25 remains Open.

Question just to make sure I do correctly.

Routing should I set to

1) MX Records
2) STATIC -> Empty Domain List -> Blackhole Hostname which is Non exist IP.

Which is better?

The disturbing part is it started as 100% Empty, now I cannot make it 100% empty as it simply won't accept.

One last port 25 to go.
__________________
Astaro Latest Version, HP ML110 G3 Server, P4HT 3.0GHz , 3GB RAM, 3 x Broadcom Gigabit NIC
Reply With Quote
  #13 (permalink)  
Old 05-16-2009, 04:28 PM
Billybob's Avatar
Wizard
 
Join Date: Jul 2006
Location: United States
Posts: 637
Default

Quote:
It used to be Static Host List but after I tried to play around, I can no longer set it back to Static Host List which is empty thus I choose MX Records
Something is not right and the webadmin is not behaving as it should. Just for FYI, I always use static host in there since it saves the firewall from making one extra query and saves on another point of failure. But that point is moot in your case since you are not allowing any from outside.

You have stated that the port is stealth if you turn off smtp all together on grc.com? In my limited testing, DNAT made port 25 stealth on 7.401 (haven't taken the plunge to 7.402) on grc. Are you sure your router doesn't have smtp port.

Just out of curiosity, how were you blocking incoming smtp on v6 without DNAT if you had smtp proxy running?

Quote:
Added Block Rule on Top in Packet Filter still remains open.
Builtin rules are always and have always been applied before manually added packet filter rules even in v6.
Reply With Quote
  #14 (permalink)  
Old 05-16-2009, 04:50 PM
Alvin's Avatar
Senior Member
 
Join Date: Jul 2003
Posts: 142
Default

Hi Billybob.

1) As I went thru the 7.402 setup from scratch several times. I am very sure this is the behavior.
1.1) During the Basic Setup Wizard, I did Not check Allow Incoming SMTp.
1.2) When log into Web Admin, the Routing is STATIC with Domain Empty and the Host List Empty.
1.3) As part of my attempt to find the right configuration, I changed to MX Record and saved sucessfully, saw that it did not meet my requirements and wanted to change back.
1.4) Now when I try to change back to Static, I can leave the list of domains empty But the Host List is a must to set something before it will save. So I set it to the "Blackhole" Hostlist I created to do the DNAT.

2) I do not have a seperate Router, Astaro is my router. It is connected to Cable Modem directly.
2.1) Yes all ports are simply closed when I disabled SMTP Proxy, absolutely sure of this.

3) During the V6, It was simple, I remember I just state I use a SMART Host and that is it.
__________________
Astaro Latest Version, HP ML110 G3 Server, P4HT 3.0GHz , 3GB RAM, 3 x Broadcom Gigabit NIC
Reply With Quote
  #15 (permalink)  
Old 05-16-2009, 09:07 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 5,390
Default

Have you tried to set a smarthost in the current version?
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #16 (permalink)  
Old 05-17-2009, 04:17 AM
RFCat_vk's Avatar
Wizard
 
Join Date: Aug 2005
Location: Victoria, Australia
Posts: 2,554
Default

Hi Alvin,
I have just finished a basic security scan of my ASG with the same website you refer to in your message and not found any open ports. I will try again with the IPS disabled and see what happens.

Ian M

I ran the "No Risk Audit". It returned one intermediate threat ??, 3 minors and 6 others. The 3 minors were all about my non existent e-mail server which happens to be my hp7150 printer. The "others" were informational only "no risk".

I did forget to add in my configuration post that I block all packet filter traffic below 1024 to ensure everything goes through the proxy. Some applications are very dumb and can't work with a proxy even when they have the ability to. I then put specific packet filter rules to allow them to talk to specific sites eg microsoft update, adobe update, Australian Tax Office (e-tax) etc.
__________________
Home Power User unlimited licence - v7.50x - AMD X2 5050e with 2gb,1 intel NIC, the onboard NIC and netgear gs108t with vlans.

Last edited by RFCat_vk; 05-17-2009 at 03:28 PM. Reason: added extra scan test results
Reply With Quote
  #17 (permalink)  
Old 05-17-2009, 03:03 PM
Alvin's Avatar
Senior Member
 
Join Date: Jul 2003
Posts: 142
Default

Hi

Balfson - Yes I added my ISP SMTP to the smarthost and looking at headers, yes it is working fine.

RFCat_vk - Ensure your port scan detection under IPS is disabled.

__________________
Astaro Latest Version, HP ML110 G3 Server, P4HT 3.0GHz , 3GB RAM, 3 x Broadcom Gigabit NIC
Reply With Quote
  #18 (permalink)  
Old 05-17-2009, 03:26 PM
RFCat_vk's Avatar
Wizard
 
Join Date: Aug 2005
Location: Victoria, Australia
Posts: 2,554
Default

Hi Alvin,
yes, I had detect portscan disabled, I also disabled the DOS rules as well.

Put them all back after I finished the tests.

Ian M
__________________
Home Power User unlimited licence - v7.50x - AMD X2 5050e with 2gb,1 intel NIC, the onboard NIC and netgear gs108t with vlans.
Reply With Quote
  #19 (permalink)  
Old 05-17-2009, 04:38 PM
Alvin's Avatar
Senior Member
 
Join Date: Jul 2003
Posts: 142
Default

RFCAT_VK

So did your SMTP Ports shows Open?
__________________
Astaro Latest Version, HP ML110 G3 Server, P4HT 3.0GHz , 3GB RAM, 3 x Broadcom Gigabit NIC
Reply With Quote
  #20 (permalink)  
Old 05-17-2009, 07:28 PM
Billybob's Avatar
Wizard
 
Join Date: Jul 2006
Location: United States
Posts: 637
Default

Ok I have repeated the same test multiple times on grc.com. All tests with antiportscan turned off

SMTP Proxy on, all ports are stealth, port 25 open
SMTP proxy off, all ports are stealth
SMTP proxy on, DNAT to no existing IP, ALL Ports Stealth Again.

Again this is all with astaro 7.401.
Attached Images
File Type: jpg stealth.jpg (13.6 KB, 10 views)
File Type: jpg astaroDNAT.JPG (45.8 KB, 12 views)
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 09:59 PM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.