Computing.Net > Forums > Novell Netware > GWIA SMTP relay hold

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

GWIA SMTP relay hold

Reply to Message Icon

Name: Lou
Date: November 14, 2002 at 19:46:48 Pacific
OS: Netware
CPU/Ram: Pentium 2, 256MB RAM
Comment:

Is there a way to check if our server was used to route/relay SPAM via our SMTP gateway? In GWIA at somepoint our 'prevent routing' was unchecked. We have fixed this, but someone is saying we are being used as a relay for SPAM, what logs can I check to verify this (or deny it).

We have the latest patches and did what the novell web site says to do.

Thank you!



Sponsored Link
Ads by Google

Response Number 1
Name: Morgan
Date: November 15, 2002 at 08:39:09 Pacific
Reply:

This is how we check for spam:

Every night at midnight when everything does it's log rotation, the GWIA.GATEWAY sends the admin an e-mail with the subject 'Agent Accounting Data File'. When reading the acct file that comes in the e-mail, we can see who sent what to whom along with the subject of the message. We are just looking for something fishy like invalid usernames or addresses.

On the server side, in GWIA we check the options to make sure that the log level is normal or verbose. Hope that helps.


0

Response Number 2
Name: Underdog
Date: November 16, 2002 at 11:14:23 Pacific
Reply:

Using NWAdmin to turn off SMTP Relaying or setting the "/No Routing" switch in the GWIA.cfg file simply do not work before version 5.5.4. Even after 5.5.4 quoting the recipient address will bypass all of GroupWise's relay controls. Novell has released a patch which is reported to fix the "quote hack" in 5.5.4. This patch WILL NOT work on earlier versions of GroupWise, or if SP4 is not installed. The name of the patch is fgwia55c.exe. It comes with a TXT file that describes the installation. If you use this patch it would be very advisable to read the TXT file before installing it. Not so much for the installation instructions. But to see if you would want to.

This is the reason that I am upgrading to GW 6.x very soon. GW 6.x takes care of the Relaying problem very well. The last thing you want is for your company or organization to end up on something like a Open Relay blacklist. It's easier to get your credit history fixed than it is to get off a blacklist. I listed a site below that you can test your Domain to see how good it is against Spammers. Good luck!

V-Peace-V

http://relays.osirusoft.com/cgi-bin/rbcheck.cgi


0

Response Number 3
Name: Justin77
Date: December 10, 2002 at 03:44:54 Pacific
Reply:

Underdog is correct. What i would suggest (and have done previously) if you are being used to relay mail, is to just blanket block the I address range that is relaying via the server. I've encountered it with 62.x.x.x and 202.x.x.x addresses within the last few months. Set up a static route from the relaying addresses, to an internal ip address that you know doesn't exist. that way it'll automatically try to route, reach nowhere and send the packets back to origin. short of downing the GWIA this is the only option i've worked out so far... about 4 clients so far and counting that those b---tards have tried relaying via....


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Novell Netware Forum Home


Sponsored links

Ads by Google


Results for: GWIA SMTP relay hold

Open relay on Groupwise 5.5 www.computing.net/answers/netware/open-relay-on-groupwise-55/2761.html

GWIA and Unauthorized Access www.computing.net/answers/netware/gwia-and-unauthorized-access/3092.html

GWIA www.computing.net/answers/netware/gwia/1131.html