Re: For Alan Cox ...

From: Simon Richter (
Date: Fri May 12 2000 - 08:22:39 EST

On Fri, 12 May 2000, Malcolm Beattie wrote:

> If ORBS finds any one host in Oxford is an open relay then ORBS
> blacklists not only that host (rightly) but *also* its smarthost:

Which is correct IMHO since this setup allows unauthorized relaying over
that host. You have also named the solution: Block alls incoming SMTP
traffic except for some known good hosts. We are using the same setup
here, with good results.

> Immediately, none of the 30000 users in Oxford can email anyone who
> uses ORBS.

Why do you use a smarthost? Outbound SMTP isn't dangerous.

> Given the number of hosts involved with hundreds of mostly autonomous
> departments and colleges, she's going to be spending even more time
> keeping all those registrations up to date and coping with the moans
> of plenty of other people who see firewalling off SMTP and not
> allowing them to run SMTP servers as fascist.

Set up two (or more :-) ) machines as a central relay which accepts mail
for all the subdomains and add them as MX hosts with lower priority than
the real mail host. Any host trying to send you mail will first try the
department server (Connection refused) and then the relay (mail accepted).
The relay then forwards the mail to the department server.

But we're getting way OT here.


