Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > Mail Security: SMTP, POP3, Antispam and Antivirus

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 06-18-2009, 06:10 PM
Junior Member
 
Join Date: Mar 2006
Posts: 12
Default Need some help setting up SMTP proxy

I am getting relay not permitted errors on inbound messages. Here are the details.
Software version is 7.202 ASG320 appliance. I am also using a barracuda, but want to add an additional layer of spam/virus protection. Currently, I am natting port 25 to my barracuda. I setup the astaro to use transparent mode and I am routing the e-mail to my barracuda with the nat translation (to the barracuda) disabled. On the relay tab I have all of my mail servers, astaros, and the barracuda listed on the allowed hosts field. I also have all of my domain users listed in the alowed users field.

Also, I have a seperate Global DNS zone setup with the MX records pointing to my public IP address which is my Astaro Wan interface..not sure if that matters.

I'm running exchange 2003 an there is no evidence that the relay is coming from my exchange server. Astaro logs have many instances of relay not permitted so I'm sure the problem is with the Astaro config.

What am I missing?

Last edited by jslaton; 06-18-2009 at 06:15 PM.
Reply With Quote
  #2 (permalink)  
Old 06-18-2009, 06:15 PM
Junior Member
 
Join Date: Sep 2004
Location: Budapest, Hungary
Posts: 9
Default

The list of your domains (that you are accepting mail for) on the Routing tab?
Reply With Quote
  #3 (permalink)  
Old 06-18-2009, 06:18 PM
Junior Member
 
Join Date: Mar 2006
Posts: 12
Default domains

I have my domain listed in the routing tab. Also I have selected route by static host and am pointing that to my barracuda.
Reply With Quote
  #4 (permalink)  
Old 06-18-2009, 06:20 PM
Junior Member
 
Join Date: Sep 2004
Location: Budapest, Hungary
Posts: 9
Default

Could you perhaps copy a bounce here? (Only the relevant parts, of course.)
Reply With Quote
  #5 (permalink)  
Old 06-18-2009, 06:24 PM
Junior Member
 
Join Date: Mar 2006
Posts: 12
Default

66.14.127.176 does not like recipient.
Remote host said: 550 Relay not permitted
Giving up on 66.14.127.176.
Reply With Quote
  #6 (permalink)  
Old 06-18-2009, 06:29 PM
Junior Member
 
Join Date: Sep 2004
Location: Budapest, Hungary
Posts: 9
Default

And 66.14.127.176 is your public IP address?

Also, how is your barracuda given on the Routing tab? (i.e. by IP address, DNS, etc.)

Another idea: what happens if you turn Verify recipients OFF on the Routing tab? (Just temporarily, of course.)
Reply With Quote
  #7 (permalink)  
Old 06-18-2009, 06:32 PM
Junior Member
 
Join Date: Mar 2006
Posts: 12
Default

66.14.127.176 is a public Ip address. Barracuda is listed by IP.


I'll give your verify recipients idea a shot. One other thing I may try is to change the verify to active directory.

I'll do both of those now and I'll post back the results.

Thanks
Reply With Quote
  #8 (permalink)  
Old 06-18-2009, 06:42 PM
Junior Member
 
Join Date: Mar 2006
Posts: 12
Default didn't work

didn't work.

All I want is my users to get inbound e-mail. Maybe I don't need anything set in the relay fields (authenticated or host based) since we really aren't relaying for any other domains?
Reply With Quote
  #9 (permalink)  
Old 06-18-2009, 07:18 PM
Junior Member
 
Join Date: Sep 2004
Location: Budapest, Hungary
Posts: 9
Default

Yes, for inbound email you don't need anything set in the relay field (it's only for mails going outside your mail domain).

If your MX record points to the public IP address of your Astaro, you also don't need transparent mode.

Also, check that the Allow upstream/relay hosts only checkbox is OFF on the Relay tab.

If these don't help, you could perhaps post a few related lines (a few lines before and after the mail is rejected) from the smtp.log.

I'm 99% sure it is not some exotic bug, just a simple wrong setting. It's just a lot harder to find without looking at your config...
Reply With Quote
  #10 (permalink)  
Old 06-18-2009, 07:30 PM
Junior Member
 
Join Date: Mar 2006
Posts: 12
Default

I used the transparent mode to intercept the messages on port 25. If don't use transparent mode won't the messages go straight to my barracuda as I have a static NAT translation directing smpt traffic to it's internal IP bypassing the Astaro alltogether? If I do disable that nat statement will the Asatro just pick up that traffic without some sort of nat statement?

One more thing...I do need to send outbound e-mails, just not from any other domains except for the one I've specificed. So do I still need to add hosts to the allowed hosts field, maybe just my exchange servers?

Sorry for all of the questions.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 11:12 AM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.