Gentoo Archives: gentoo-user

From: Pandu Poluan <pandu@××××××.info>
To: Gentoo-user@l.g.o
Subject: [gentoo-user] Portknock before Postfix delivery?
Date: Mon, 04 Jul 2011 01:32:36
Message-Id: CAA2qdGXHV9_zu0YNsX5c5rFVE2yu-E1t5TA+6T2P=DEiwaGApA@mail.gmail.com
1 I'm just wondering...
2
3 I'm implementing an email gateway using postfix. The gateway lives as
4 a VM in my ISP, and it will deliver 'accepted' emails to the company's
5 email server which lives in the DMZ. The email server's port is
6 shifted to a non-25 external port number.
7
8 So far so good. However, a portscanner might still be able to detect
9 which port is open and attempt deliveries there.
10
11 So, the question: Is it possible to configure the system in some way
12 so that Postfix will first perform a portknocking before attempting
13 delivery to the internal mail server?
14
15 If that is not possible, what solution would you recommend to 'harden'
16 the non-25 mail port?
17
18 Rgds,
19
20
21 --
22 --
23 Pandu E Poluan - IT Optimizer
24 My website: http://pandu.poluan.info/

Replies

Subject Author
Re: [gentoo-user] Portknock before Postfix delivery? Walter Dnes <waltdnes@××××××××.org>
Re: [gentoo-user] Portknock before Postfix delivery? Neil Bothwick <neil@××××××××××.uk>
Re: [gentoo-user] Portknock before Postfix delivery? Michael Orlitzky <michael@××××××××.com>