I have a bit of a problem and I am at a loss as to how to fix it.
It would seem that my Astaro firewall is being used as an open mail relay.
About a month ago my ISP reported that in two days I had a usage of over 750MB.
I did some changes to my filters and to the SMTP relay settings and all seemed to be fine after making these changes and I put it all down to experience (or maybe I should have said lack of experience).
This week it happened again. I was hit with 250MB in a day that was not mine.
After the last attack I enabled accounting to try and track as much as I could but this does not seem to have helped.
My environment is as follows:
Netgear NAT router in front of the Astaro box
Windows 2000 AD server with Exchange 2000 server installed behind Astaro.
The Exchange server is definitely set not to relay and does not send NDRs out of the internal network. NDRs are only sent to the administrator.
The Astaro box is configured as follows:
SMTP Relay enabled
SMTP routes table is set to my domain and the SMTP host is configured in Networks as ExchangeServer (specified as the Exchange server’s IP address)
No networks are selected in the Outgoing Mail (empty list)
Sender address verification is enabled
I do not know what else I can configure!
When I get hit I can neither confirm or deny if the Astaro box is relaying mail.
I get multiple message stuck in the SMTP queue. Some frozen, some bounced.
As I said, I cannot confirm that the Astaro box is relaying mail but other than sending multiple NDRs back to the originating address I have no other explanation as to how my usage could have been as high as it was.
I am open to suggestions and even more interested if finding a way to stop this from happening again.
Another thing. Is it possible to stop Astaro from sending NDRs? I would like to configure it the same way I have configured Exchange so that any NDRs that are created are only sent to the administrator internally. Is this possible?
Any suggestions are welcome.
This thread was automatically locked due to age.