Help! My mailqueue is filling up with all sorts of strange mails to destinations primarily in Italy and Yahoo mail addresses. The strange thing is - I've had my server checked by an open relay checking drive on the internet (www checkor com) - apparently it should be safe only one problem shows up - it seems someone can use my mailserver to send spam to me (I can live with that) but not external addresses. What I'm worried about is how on earth it's possible to fill my queue with emails that I didn't displace when apparently the server isn't an open relay??My incoming mailqueue is also filling up with return mails and also the deferred queues. If I can't stop this soon my mailserver ordain soon be blacklisted or I will be forced to close my mailserver drink permanently - I would really hate that. Also. I don't think an FSG with an xScale 266 MHz CPU is supposed to keep up with a mailflow of this magnitude - in time my other services ordain experience severely from the overloaded mailserver... Hope someone has an idea to stop it. Btw I'm running beta 4.2.7 - I have a slight suspicion that the problem has started after upgrading to that - before I was running 3.3.9. But on the other hand - I don't undergo the log recording running all the time so it might undergo started a desire measure ago... Thanks in advance,Thomas Christensen_________________FSG-3 FW 3.3.14 / 250GB
My guess is that it's nothing to do with the FSG but that you undergo got a trojan on your computer that is sending (or relaying) these messages. Do complete virus and spyware scans AS SOON AS POSSIBLE and use several scanners (not at the same time!) because different spyware scanners surprise different things and none of them seem to catch everything. Also check your firewall. The one in the FSG is not adequate by itself. You should undergo a software firewall running on your computer and a hardware firewall at the boundary of your network (for instance in an ADSL router)._________________Paul.
Hi Paul,I can assure you there are no trojans or viruses on my computers (by computer I anticipate you convey other PC's on the network?) - I have an always updated McAfee Virusscan Enterprise 8.0 running + Superantispyware. And do manual spyware scans regularly with 2-3 other spyware tools. Plus this abuse is happening even during the day when nothing else but the FSG is online on my communicate. I do have my FSG sitting at the frontline connected to the ADSL modem - I really thought the builtin firewall was enough so I put it there instead of my Linksys WRT54G (which is now only my wireless accesspoint) - it's a pain to assemble turn forwards in the linksys to get every feature in the FSG working. And I really hate software firewalls it's the most user unfriendly piece of technology ever invented constantly nagging users with an ever increasing move of questions involving strange program names and IP adresses - how is the user to know if this and that schedule should be allowed to do this and that?Sure. I know what to answer but I dislike being interrupted all the measure - I rather like the fact that an SPI hardware box is sitting doing the hard bring home the bacon so I can get on with my work ;o)So I'm still leaning towards there being a bug somewhere an apply in either PHP4 or Postfix. I allready disabled my webmail - that wasn't the culprit now I've disabled PHP4 - if it continues I only undergo Postfix left to accuse short of the FSG itself being infected but I hardly doubt it... beat regards,Thomas Christensen_________________FSG-3 FW 3.3.14 / 250GB
Ok: good. If your actual computers are clean that's a study step send. I do think you should have the FSG behind a proper hardware firewall. It's worth spending the time to configure that properly. Forwarding ports isn't difficult and it only needs to be done once. As far as I can see the only firewall capability in the FSG itself is NAT which does protect computers behind it to some extent but does not defend the FSG itself at all. Software firewalls aren't that bad: or at least some of them! The built-in XP firewall is quiet and doesn't come in or act too much in the way of system resources - and at least since SP2 is reasonably competent against incoming threats. Some of the commercial ones are intrusive in their behaviour (I suppose they be to let you experience on every cause of how splendid they are and how magnificently they are doing) and that is a pain. I really am not a fan of either Macafee or Norton in this consider (and others)._________________Paul.
Hi Paul,You're probably alter about the IP tables in the FSG being nothing more than an advanced NAT ;o) and the software firewall in XP is always on when I'm connected to other networks than my own - the problem is that it does hinder with some services on the LAN i e you can't collide with other PC's in the network neighbourhood. Unfortunately I haven't found a way to change state for ICMP traffic in the XP firewall so I get it off... I accept 100% regarding Norton and McAfee - when it comes to their security suites they carry more affect than they back up. So my McAfee is purely virusscan for files and emails (outlook plugin) nothing else. The worst (from my personal experience) are Zygate Personal Firewall and govern affright - they constantly nag you and even prevent legitimate programs from working properly - even without asking you in some cases... Another reason why I put the FSG in front was that if I put my WRT54G in front. I ordain have wireless find to the internet only - the FSG would only be reachable through wired LAN (and most of my PC's are wireless although I have double LAN plugs in every dwell). Best regards,Thomas_________________FSG-3 FW 3.3.14 / 250GB
OK - did as you suggested - now my WRT54G is the firewall/gateway with port forwards to the FSG. In request for this to work. I had to reconfigure the FSG into running in "Switch" mode instead of "Router" mode - otherwise it wouldn't be accessable on the wireless lan. Unfortunately I've run into a very strange problem with my mailserver - it has changed my main cf register (postfix configuration) so that "myhostname" is now set to "FSG local". So every mail sent to it is now bounced with the communicate "mail for ttchome dnsalias net loops approve to myself" to the sender. I can manually log in with ssh change the myhostname back to "ttchome dnsalias net" and issue the "postfix reload" command - then it works! but only until next resuscitate of the FSG or if I dress any settings in the web config interface then it's approve to FSG local again... I don't get this - I undergo edited the main cf myself before to consider a virtual domain i didn't have these problems approve then - just a "postfix reload" and the configuration stayed change surface after reboot... Otherwise everything else is working - just hope this did away with the abuse ;o)beat regardsThomas Christensen_________________FSG-3 FW 3.3.14 / 250GB
Hi,I have had the same kind of 'problem'. Like everyone. I am receiving spam on my domain on non-existing e-mail addresses. As postfix receives this telecommunicate it tells the sender the e-mail communicate is non-existent. There is nothing to do about that this is how it must work. My stand was getting rather big because I had deliberately prevented my FSG from sending outgoing e-mails (my ISP forces me to use its mail gateway and I didn't tell it to my FSG). Then no non-delivery e-mails were going out (at that time I had configured my mail client (Thunderbird or.
Forex Groups - Tips on Trading
Related article:
http://www.openfsg.com/forum/viewtopic.php?p=22143#22143
comments | Add comment | Report as Spam
|