Hi,
does ASL 7 not contain the Verify recipient feature like
6.X?
cu SveN
This thread was automatically locked due to age.
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.
No, I'm not confused, it was the Verify RCPT option that I am thinking about. All I know is Astaro Support told me it was a bad idea to have it on.. after they explained why, it made perfect sense. Mail servers sometimes send NDRs when the Verify RCPT is run; a spammer could randomly generate email addresses, and when they didn't get an NDR back, they would know they had a valid address... automate that, and suddenly your Astaro is flooded with requests.. I had this happen to a customer with a 220, and it brought it to it's knees.
---hmmm just read what drees just posted.. interesting... Astaro Support must've been wrong, or is not heeding their own advice to me. All I know is that once that was turned off, the traffic gradually went down.
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.
I just tested it, looks like it verifies the recipient by default which is good. [:)]
Although, before I entered a valid gateway on the system it didn't verify the recipient which had me confused for a while.
2007:02:07-08:35:11 (none) exim[10531]: 2007-02-07 08:35:11 SMTP connection from [192.168.***.***]:1729 (TCP/IP connection count = 1)
2007:02:07-08:35:12 (none) exim[11564]: 2007-02-07 08:35:12 [pid 11564] [192.168.***.***] F= Trusted (sent from relay or localhost)
2007:02:07-08:35:12 (none) exim[11564]: 2007-02-07 08:35:12 [pid 11564] [192.168.***.***] F= R= Accepted: from relay
2007:02:07-08:35:12 (none) exim[11564]: 2007-02-07 08:35:12 1HEhKi-00030W-3P unknown@recdomain.com F= P= R=cff_route T=cff_smtp H=127.0.0.1 [127.0.0.1]:1234
2007:02:07-08:35:12 (none) exim[11565]: 2007-02-07 08:35:12 1HEhKi-00030W-3P Completed
2007:02:07-08:35:15 (none) exim[11572]: 2007-02-07 08:35:15 SMTP connection from MailerDaemon
2007:02:07-08:35:15 (none) exim[11572]: 2007-02-07 08:35:15 1HEhKl-00030e-Ld P= R=static_route_hostlist T=static_smtp: SMTP error from remote mail server after RCPT TO:: host 192.168.YYY.YYY [192.168.YYY.YYY]: 550 No such recipient
2007:02:07-08:35:15 (none) exim[11578]: 2007-02-07 08:35:15 1HEhKl-00030k-Sv <> R=1HEhKl-00030e-Ld U=exim P=local S=108534
2007:02:07-08:35:15 (none) exim[11573]: 2007-02-07 08:35:15 1HEhKl-00030e-Ld Completed
2007:02:07-08:35:16 (none) exim[11579]: 2007-02-07 08:35:16 1HEhKl-00030k-Sv => fromuser@domain.com F=<> P=<> R=cff_route T=cff_smtp H=127.0.0.1 [127.0.0.1]:1234
2007:02:07-08:35:16 (none) exim[11579]: 2007-02-07 08:35:16 1HEhKl-00030k-Sv Completed
2007:02:07-08:35:18 (none) exim[11597]: 2007-02-07 08:35:18 SMTP connection from MailerDaemon
2007:02:07-08:35:18 (none) exim[11597]: 2007-02-07 08:35:18 1HEhKo-000313-Rj <> U=MailerDaemon P=local-bsmtp S=108728 id=E1HEhKl-00030k-Sv@asl7.recdomain.com
2007:02:07-08:35:19 (none) exim[11598]: 2007-02-07 08:35:19 1HEhKo-000313-Rj => fromuser@domain.com F=<> P=<> R=smarthost_route T=remote_smtp H=192.168.ZZZ.ZZZ [192.168.ZZZ.ZZZ]:25 X=TLSv1:AES256-SHA:256
2007:02:07-08:35:19 (none) exim[11598]: 2007-02-07 08:35:19 1HEhKo-000313-Rj Completed
To me it seems that Verify recipient feature is *NOT* turned on?
Look at this log:
2007:02:07-08:35:12 (none) exim[11564]: 2007-02-07 08:35:12 [pid 11564] [192.168.***.***] F= Trusted (sent from relay or localhost)
ASL Accepts the Mails and then generates a Mail Delivery failure Message?
But, is there a way to prevent the firewall from bouncing a message back to the sender if the recipient address is rejected?
This message was created automatically by the SMTP relay on firewall.yyy.com.
A message that you sent could not be delivered to all of its recipients.
The following address(es) failed:
aaa@yyy.com
SMTP error from remote mail server after RCPT TO::
host 192.168.***.*** [192.168.***.***]: 550 :
Recipient address rejected: User unknown in local recipient table
As said before: Astaro does not validate the recipient for trusted hosts/networks.
2007:02:08-22:55:40 (none) exim[27962]: 2007-02-08 22:55:40 SMTP connection from [65.***.***.***]:3661 (TCP/IP connection count = 1)
2007:02:08-22:55:41 (none) exim[16986]: 2007-02-08 22:55:41 [pid 16986] [65.***.***.***] F= Untrusted message
2007:02:08-22:55:41 (none) exim[16986]: 2007-02-08 22:55:41 [pid 16986] [65.***.***.***] F= R= Verifying recipient address
2007:02:08-22:55:41 (none) exim[16986]: 2007-02-08 22:55:41 [pid 16986] [65.***.***.***] F= R= Greylisting: skipped for this domain
2007:02:08-22:55:41 (none) exim[16986]: 2007-02-08 22:55:41 1HFHEz-0004Py-91 unknownuser@domain.org F= P= R=cff_route T=cff_smtp H=127.0.0.1 [127.0.0.1]:1234
2007:02:08-22:55:41 (none) exim[16987]: 2007-02-08 22:55:41 1HFHEz-0004Py-91 Completed
2007:02:08-22:55:43 (none) exim[16991]: 2007-02-08 22:55:43 SMTP connection from MailerDaemon
2007:02:08-22:55:43 (none) exim[16991]: 2007-02-08 22:55:43 1HFHF1-0004Q3-7a <> R=1HFHF1-0004Q3-7a U=exim P=local S=5290
2007:02:08-22:55:43 (none) exim[16992]: 2007-02-08 22:55:43 1HFHF1-0004Q3-7a Completed
2007:02:08-22:55:43 (none) exim[16997]: 2007-02-08 22:55:43 1HFHF1-0004Q8-BP => fromuser@domain.com F=<> P=<> R=cff_route T=cff_smtp H=127.0.0.1 [127.0.0.1]:1234
2007:02:08-22:55:43 (none) exim[16997]: 2007-02-08 22:55:43 1HFHF1-0004Q8-BP Completed
2007:02:08-22:55:45 (none) exim[17008]: 2007-02-08 22:55:45 SMTP connection from MailerDaemon
2007:02:08-22:55:45 (none) exim[17008]: 2007-02-08 22:55:45 1HFHF3-0004QK-Cb <> U=MailerDaemon P=local-bsmtp S=5490 id=E1HFHF1-0004Q8-BP@firewall.domain.org
2007:02:08-22:55:53 (none) exim[17009]: 2007-02-08 22:55:53 1HFHF3-0004QK-Cb => fromuser@domain.com F=<> P=<> R=dnslookup T=remote_smtp H=mail.emps.equant.com [207.***.***.***]:25 X=TLSv1[:D]HE-RSA-AES256-SHA:256
2007:02:08-22:55:53 (none) exim[17009]: 2007-02-08 22:55:53 1HFHF3-0004QK-Cb Completed