Re: [Exim] When the lowest numbered MX is firewalled.

Top Page
Delete this message
Reply to this message
Author: Philip Hazel
Date:  
To: Thorkild Stray
CC: exim-users
Subject: Re: [Exim] When the lowest numbered MX is firewalled.
On 30 Aug 2001, Thorkild Stray wrote:

> adm.mail.com          MX      5 gw.mail.com
> adm.mail.com          MX      10 recv.mail.com

>
> gw.mail.com does not allow connections directly to itself, it is
> firewalled. To send mail, one must send it to recv.mail.com, which is
> allowed to connect to the gw directly.


DON'T DO THIS! Sorry for shouting, but this is something that is
*really* annoying. It means that every MTA in the world that is trying
to send to you is going to try gw.mail.com first, and waste time and
resources timing out, before it tries the second MX.

> The problem is when this has been going on for a while. Then the
> "gw.mail.com" machine is blacklisted in Exim and it is bounced with:


Quite right. Sorry to be hard here, but I think this is your problem,
not Exim's problem.

There should never be an MX in the publicly-visible DNS for an MTA that
cannot be accessed by everybody.


-- 
Philip Hazel            University of Cambridge Computing Service,
ph10@???      Cambridge, England. Phone: +44 1223 334714.