
Code Blue
•
259 Hedcor Street
•
Holland, MI 49423 USA
•
800.205.7186
•
www.codeblue.com GU-154-F
page 129 of 132
ToolVox® X3
Administrator Guide
Debugging features
Postxhastwolevelsoflogging.Therstlevelisthenormalmaillog,whichreportsonallnormal
mailactivities,suchasreceivedandsentmail,servererrors,shutdownsandstartups.Thesecond
levelismoreverboseandcanbetunedtologactivityrelatingtospecicSMTPclients,hostnames
oraddresses.Thispagecontainsthecongurationforthesecondleveloflogging.
List of domain/network patterns for which verbose log is enabled
Thisisalistofpatternsoraddressesthatmatchtheclients,hostsoraddresseswhoseactivityyou
wouldliketohavemoreverboseloggingfor.ValuescouldbeanIPaddresslike192.168.1.1or
adomainnamelikeswelltech.com.Thisoptioncorrelatestothedebug_peer_listdirectiveandis
emptybydefault.
Verbose logging level when matching the above list
Speciesthelevelofverbosityoftheloggingfortheactivitythatmatchestheabovepatterns.This
optioncorrelatestothedebug_peer_leveldirectiveanddefaultsto2.Theaboveeldmusthaveat
leastonevalueforthisdebugleveltohaveanyimpact.
Postfix, Unsolicited Commercial Email and Access Controls
Postxoffersanextremelyexiblesetofaccesscontrols,primarilytargetedatpreventingunsolicited
commercialemailfrombeingdeliveredthroughtheserver.Inordertoconstructasuitablesetof
controls,itisnecessarytounderstandtheorderrulesarecheckedandhowtheyinteract.Bydefault,
Postxwillacceptmailfordeliveryfromortoanyclientonyourlocalnetworkandanydomainsthat
arehostedbyPostx.So,bydefault,Postxisnotanopenrelay.Thisisagoodbeginningandall
thatisneededinmanyenvironments.However,becauseUCEissuchanuisanceforusersand
networkadministrators,itmaybeworthwhiletoimplementmoreadvancedltering.Thissectionwill
addressthebasicsofthePostxUCEcontrolfeatures.
Access Control List Order
Everymessagethatentersthesmtpddeliverydaemonwillbeprocessedbyaccesscontrollists
andcheckedagainstrulestoensurethatthemessageisonethattheadministratoractuallywants
delivered.Thegoalformostadministratorsistopreventunsolicitedcommercialemailfrompassing
throughtheserules,yetallowlegitimateemailstobedelivered.Thisisaloftygoal,andadelicate
balance.Noperfectsolutionexistsaslongaspeoplearewillingtostealresourcesfortheirown
commercialgainandgotogreatlengthstoovercometheprotectionsinplacetopreventsuch
abuse.However,inmostenvironmentsitispossibletodevelopareasonablesetofrulesthat
preventsmostspamandallowsmostoralllegitimatemailthroughunharmed.
Itisimportanttounderstandtheorderofprocessingifcomplexsetsorrulesaretobeused,as
attemptingtousearuletooearlyinthechaincanleadtosubtleerrorsorstrangemailclient
behavior.Becausenotallclientsreactcorrectlytosometypesofrefusals,andnotallclientscreate
correctlyformedSMTPrequests,itisnotunlikelythatamisplacedrulewilllockoutsomeorall
ofyourclientsfromsendinglegitimatemail.Itcouldalsoleadtoopeningaholeinyourspam
protectionsearlyintheruleset,whichwouldallowillicitmailtopass.
ThePostxUCEcontrolsbeginwithacoupleofsimpleyesornochecks,calledsmtpd_helo_
requiredandstrict_rfc821_envelopes,bothconguredintheSMTP Server Optionspage.Therst,
ifenabled,requiresaconnectingmailclienttointroduceitselffullybysendingaHELOcommand.
Kommentare zu diesen Handbüchern