Forum Discussion
jfrizzell_43066
Nimbostratus
Dec 08, 2014iRule SMTP Help
I am in need of a little help preventing an open SMTP Relay with the F5. I will give you some background information to the setup. We currently have a pool of 10 servers in our farm and it's currentl...
- Dec 08, 2014
So in an effort to correct this problem, I changed the snat automap in the iRule to reject and drop. This however didn't correct the issue and everyone inside and outside of the data groups can connect.
i think it should work. can you try this?
when CLIENT_ACCEPTED { if { [ class match [IP::client_addr] equals smtp_all_allowed ] } { snatpool smtp_allowed } elseif { [ class match [IP::client_addr] equals smtp_internal_only ] } { snatpool smtp_internal } else { reject } }
nitass
Employee
Dec 08, 2014So in an effort to correct this problem, I changed the snat automap in the iRule to reject and drop. This however didn't correct the issue and everyone inside and outside of the data groups can connect.
i think it should work. can you try this?
when CLIENT_ACCEPTED {
if { [ class match [IP::client_addr] equals smtp_all_allowed ] } {
snatpool smtp_allowed
} elseif { [ class match [IP::client_addr] equals smtp_internal_only ] } {
snatpool smtp_internal
} else {
reject
}
}
- jfrizzell_43066Dec 11, 2014
Nimbostratus
Just tested it and it appears to be working. Thanks for the help.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects