Solved

How to block port 25 for all machine except the mailserver

Posted on 2009-03-31
2
860 Views
Last Modified: 2013-12-06
I like to block the port 25 on our firewall so no other than the real email server can send emails

Considering that the mail server address is 10.0.0.1, the gateway is 10.0.0.254 and the gateway that connects to the internet through the router has the IP of 192.168.0.100
So the machine that is running IPTables is on 10.0.0.254 and the external nic is 192.168.0.100
What should my rule look like?

TIA,

Tom
0
Comment
Question by:tom_szabo
2 Comments
 
LVL 16

Accepted Solution

by:
Blaz earned 500 total points
ID: 24036457
iptables -I FORWARD -p tcp --dport 25 -j DROP
iptables -I FORWARD -s 10.0.0.1 -p tcp --dport 25 -j ACCEPT

This rules will drop every connection to port 25 if not comming from your email server. Note that I wrote "-I" which means insert at the beginning - the rules will be reversed in the FORWARD chain.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Hello EE, Today we will learn how to send all your network traffic through Tor which is useful to get around censorship and being tracked all together to a certain degree. This article assumes you will be using Linux, have a minimal knowledge of …
The purpose of this article is to show how we can create Linux Mint virtual machine using Oracle Virtual Box. To install Linux Mint we have to download the ISO file from its website i.e. http://www.linuxmint.com. Once you open the link you will see …
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now