- Votre domaine internet : exemple.net - Votre MX : mx1.exemple.net - L'adresse IP de votre messagerie locale : 192.168.10.10 - Email normal : normal@exemple.net - Votre interface eth0, dédié au WAN : 192.168.1.10 - Votre interface eth1, dédié au LAN : 192.168.1.20
telnet 192.168.1.10 25 > 220 mx1.exemple.net HELO hote.test.com > 250 mx1.exemple.net MAIL FROM:<mail.exterieur@domain.net> > 250 2.1.0 Ok RCPT TO:<normal@exemple.net> > 250 2.1.5 Ok DATA Subject: Test mail normal test . > 250 2.0.0 Ok: queued as C8895AA093B QUIT > 221 2.0.0 Bye > Connection closed by foreign host.
telnet 192.168.1.10 25 > 220 mx1.exemple.net HELO hote.test.com > 250 mx1.exemple.net MAIL FROM:<mail.exterieur@domain.net> > 250 2.1.0 Ok RCPT TO:<normal@exemple.net> > 250 2.1.5 Ok DATA Subject: Test spam XJS*C4JDBQADN1.NSBN3*2IDNEN*GTUBE-STANDARD-ANTI-UBE-TEST-EMAIL*C.34X . > 250 2.0.0 Ok: queued as C8895AA093B QUIT > 221 2.0.0 Bye > Connection closed by foreign host.
tail -500 /var/log/maillog | grep 'SPAM'
telnet 192.168.1.10 25 > 220 mx1.exemple.net HELO hote.test.com > 250 mx1.exemple.net MAIL FROM:<mail.exterieur@domain.net> > 250 2.1.0 Ok RCPT TO:<normal@exemple.net> > 250 2.1.5 Ok DATA Subject: Test virus X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H* . > 250 2.0.0 Ok: queued as C8895AA093B QUIT > 221 2.0.0 Bye > Connection closed by foreign host.
tail -500 /var/log/maillog | grep 'INFECTED'
telnet 192.168.1.10 25
> 220 mx1.exemple.net
HELO hote.test.com
> 250 mx1.exemple.net
MAIL FROM:<mail.exterieur@domain.net>
> 250 2.1.0 Ok
RCPT TO:<normal@exemple.net>
> 250 2.1.5 Ok
DATA
Subject: Test banned
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_Part_28089_18724939.1217414718223"
------=_Part_28089_18724939.1217414718223
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
test
------=_Part_28089_18724939.1217414718223
Content-Type: application/octet-stream; name=Message-fichier-interdit.mdw
Content-Transfer-Encoding: base64
X-Attachment-Id: f_fj9t9ypi0
Content-Disposition: attachment; filename=Message-fichier-interdit.mdw
dmFyIHRlc3QgPSAnMSc7
------=_Part_28089_18724939.1217414718223--
.
> 250 2.0.0 Ok: queued as C8895AA093B
QUIT
> 221 2.0.0 Bye
> Connection closed by foreign host.
tail -500 /var/log/maillog | grep 'BANNED'
telnet 192.168.1.20 25 > 220 mx1.exemple.net HELO mondomain.net > 250 mx1.exemple.net MAIL FROM:<normal@exemple.net> > 250 2.1.0 Ok RCPT TO:<mail.exterieur@domain.net> > 250 2.1.5 Ok DATA Subject: Test mail sortant test . > 250 2.0.0 Ok: queued as C8895AA093B QUIT > 221 2.0.0 Bye > Connection closed by foreign host.
vi /var/rs/addons/postgrey/etc/whitelist_clients 192.168.10.50 radicalspam reload_postgrey
tail -500 /var/log/maillog | grep postgrey | grep action Vous devriez trouver une ligne contenant : action=pass, reason=client whitelist ...
(en cours...)
(en cours...)